In openclaw versions up to and including 2026.2.22-2, a non-default exec-approval configuration could allow a skill-name collision to bypass an ask=on-miss prompt.
When autoAllowSkills=true, a path-scoped executable such as ./skill-bin could resolve to basename skill-bin, satisfy the skills allowlist segment, and run without prompting for approval.
npm openclaw<= 2026.2.22-2>= 2026.2.23 (released)This behavior requires non-default settings and does not affect default installs.
Required conditions:
autoAllowSkills=true (default is false)system.run with security=allowlistask=on-missThe allowlist evaluator accepted skills satisfaction by bin-name match, so ./skill-bin could match skillBins.has("skill-bin") after resolution.
The fix hardens skill auto-allow matching by requiring:
/ or \\), andThis preserves normal skill-bin ... behavior while preventing ./<skill-bin> and absolute-path basename collisions from auto-satisfying skills.
In affected non-default configurations, approval prompts could be skipped for commands that should have required operator confirmation.
ffd63b7a2c4c6d5aeb4710ef951d5794ad7ad77b (fix(security): trust resolved skill-bin paths in allowlist auto-allow)OpenClaw thanks @tdjackey for reporting.
{
"cwe_ids": [
"CWE-266",
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-03T22:13:53Z",
"nvd_published_at": null,
"severity": "HIGH"
}