OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100598

HIGH · CVSS 7.1 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The OpenClaw npm package prior to version 2026.7.1 is vulnerable due to improper binding of Signal approval reactions, which can lead to misinterpretation of an approver's reactions to unrelated messages as approvals or denials of pending actions. This could result in unintended consequences depending on the context of the conversation and the nature of the pending requests. Organizations using OpenClaw for structured approval processes should prioritize updating to version 2026.7.1 to mitigate the risk of erroneous actions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100598
Severity
HIGH
CVSS
7.1
EPSS
0.11%

Original NVD Description

OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could instead attach to ordinary outbound text when unrelated outbound messages and a pending approval are present in the same conversation. As a result, an approver's reaction to unrelated text could be interpreted as approving or denying a pending host action; the practical impact depends on the pending request, conversation timing, and the actions available to the OpenClaw process. The issue does not change the authority of correctly identified approvers. This is fixed in version 2026.7.1.