🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: Node.js / npm

Mô tả

OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. In affected versions, filename generation created an embedded helper that retained tools which the originating sender's policy had removed. When session-memory filename generation was enabled for an agent reachable by lower-trust senders, model-mediated instructions could cause the helper to invoke tools outside that sender's effective policy; the demonstrated impact was the creation of persistent scheduled work. Exploitability depends on the model acting on the injected instruction and on which tools the helper exposes. The issue is fixed in 2026.8.1; as a workaround, disable session-memory filename generation for agents reachable by lower-trust senders.

Chi tiết

Trạng tháiDeferred
Điểm CVSS5.3 (v3.1)
Vector CVSSCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Ngày công bố10:17 26/09/2026
Ngày cập nhật22:23 28/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-863

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
22:27 28/09/2026 CREATED cve MEDIUM

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).