CVE-2026-27545
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| npm | openclaw | <2026.2.26 | 2026.2.26 |
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-f7ww-2725-qvw2
- https://nvd.nist.gov/vuln/detail/CVE-2026-27545
- https://github.com/openclaw/openclaw/commit/4b4718c8dfce2e2c48404aa5088af7c013bed60b
- https://github.com/openclaw/openclaw/commit/4e690e09c746408b5e27617a20cb3fdc5190dbda
- https://github.com/openclaw/openclaw/commit/78a7ff2d50fb3bcef351571cb5a0f21430a340c1
- https://github.com/openclaw/openclaw/commit/d06632ba45a8482192792c55d5ff0b2e21abb0a7
- https://github.com/openclaw/openclaw/commit/d82c042b09727a6148f3ca651b254c4a677aff26
- https://github.com/openclaw/openclaw
- https://www.vulncheck.com/advisories/openclaw-approval-bypass-via-parent-symlink-current-working-directory-rebind
Verify integrity in audit chain (admin only). AS-IS.