CVE-2026-100585 Overview
CVE-2026-100585 is a missing authorization vulnerability [CWE-862] in the openclaw npm package before version 2026.7.1. The package fails to enforce owner-only authorization for Claude Code permission prompts delivered through the Model Context Protocol (MCP) channel bridge. An authorized non-owner channel sender with channel command access can approve or deny a pending permission request intended for the owner. The approved action then proceeds without owner consent. The impact depends on the pending action and the host capabilities requested by the Claude Code run. The maintainers fixed the issue in openclaw2026.7.1.
Critical Impact
A non-owner channel participant can authorize sensitive Claude Code actions on behalf of the owner, enabling unauthorized command execution within the host's capability scope.
Affected Products
- OpenClaw (npm package openclaw) versions prior to 2026.7.1
- Deployments exposing the MCP channel bridge for Claude Code permission prompts
- Multi-user channel environments where non-owner senders hold channel command access
Discovery Timeline
- 2026-09-26 - CVE-2026-100585 published to the National Vulnerability Database (NVD)
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100585
Vulnerability Analysis
OpenClaw bridges Claude Code sessions to chat channels through the MCP channel integration. When Claude Code requests permission for a sensitive action, OpenClaw sends a prompt into the configured channel so the owner can approve or deny the request. The authorization check that enforces owner identity on the response is missing, so any sender with channel command access can respond. The approval or denial is honored as if issued by the owner, and the pending action proceeds within the host's granted capabilities. This is a classic authorization gap [CWE-862] in a human-in-the-loop control, which converts a user-mediated safeguard into an attacker-reachable approval surface.
Root Cause
The permission handler validates that the responder is a recognized channel participant with command privileges, but does not validate that the responder identity matches the owner tied to the pending Claude Code session. The owner-binding check is absent from the response resolution path.
Attack Vector
An authenticated non-owner participant in the shared channel issues the approval or denial command while a permission prompt is pending. Because the request is network-reachable and requires only low privileges, exploitation requires the attacker to already have channel command access and some user interaction to time the response. Successful exploitation grants the attacker influence over whatever action Claude Code requested, which may include file writes, command execution, or external calls permitted by the host.
No verified exploit code is available. See the GitHub Security Advisory and the VulnCheck Advisory for additional technical detail.
Detection Methods for CVE-2026-100585
Indicators of Compromise
- Approvals or denials in the MCP channel bridge issued by sender identities that do not match the Claude Code session owner.
- Unexpected Claude Code tool invocations (file writes, shell commands, outbound requests) immediately following a channel approval event.
- Installed openclaw package version below 2026.7.1 in package.json or package-lock.json.
Detection Strategies
- Correlate MCP channel approval events with the session owner identity recorded by OpenClaw and alert on mismatches.
- Inventory Node.js environments for the openclaw dependency and flag any version earlier than 2026.7.1.
- Baseline normal responders per channel and alert on new identities responding to permission prompts.
Monitoring Recommendations
- Forward OpenClaw and MCP bridge logs into a central logging or SIEM pipeline with the responder identity and session owner fields preserved.
- Monitor host process activity initiated by Claude Code runs for execution of unexpected binaries, file modifications outside project scope, or outbound network connections.
- Review chat channel audit logs for command usage by non-owner members during active Claude Code sessions.
How to Mitigate CVE-2026-100585
Immediate Actions Required
- Upgrade openclaw to version 2026.7.1 or later across all environments running the MCP channel bridge.
- Restrict channel command access to the Claude Code session owner until the upgrade is deployed.
- Audit recent permission approvals in affected channels and validate that actions executed by Claude Code were owner-intended.
Patch Information
The vulnerability is fixed in openclaw2026.7.1. Upgrade using npm install openclaw@2026.7.1 or update the pinned version in package.json and regenerate the lockfile. Refer to the GitHub Security Advisory GHSA-p5g8-m35v-7m82 for release notes.
Workarounds
- Limit the MCP channel bridge to private channels where the only member with command access is the Claude Code session owner.
- Disable the channel bridge integration until the patched version is deployed, and respond to Claude Code permission prompts locally.
- Reduce the host capabilities granted to Claude Code runs so that an unauthorized approval cannot trigger high-impact actions.
# Upgrade openclaw to the patched release
npm install openclaw@2026.7.1
npm ls openclaw
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.