PT-2026-99223 · Openclaw · Openclaw
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.7.1
Description
Insufficient validation of owner authorization occurs within the Codex computer-use installation command. This allows senders in a channel who are not owners to install arbitrary plugins and execute Model Context Protocol (MCP) processes—a standard for connecting AI models to external data sources—using the privileges of the OpenClaw user. This issue impacts the confidentiality, integrity, and availability of the host system.
Recommendations
Update to version 2026.7.1.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw