Report: CVE-2026-42423 - OpenClaw < 2026.4.8 - strictInlineEval Approval Boundary Bypass via Approval-Tim...

Report: CVE-2026-42423 - OpenClaw < 2026.4.8 - strictInlineEval Approval Boundary Bypass via Approval-Tim...

CVE ID :CVE-2026-42423 Published : April 28, 2026, 7:37 p.m. | 1 hour, 2 minutes ago Description :OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements on gateway and node exec hosts. Attackers can exploit this timeout fallback to execute inline eval commands that should require explicit user approval, circumventing the intended security boundary. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
April 28, 2026