PT-2026-99234 · Openclaw · Openclaw
CVSS v4.0
7.5
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openclaw versions prior to 2026.7.1
Description
The software incorrectly binds Signal approval reactions. When unrelated outbound messages and a pending approval exist in the same conversation, a reaction intended for a structured approval request may attach to ordinary outbound text. This can lead to an approver's reaction to unrelated text being interpreted as approving or denying a pending host action, depending on the request, conversation timing, and available process actions. This issue does not alter the authority of identified approvers.
Recommendations
Update to version 2026.7.1.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw