The OpenClaw ACP client could auto-approve tool calls based on untrusted metadata and permissive name heuristics. A malicious or compromised ACP tool invocation could bypass expected interactive approval prompts for read-class operations.
openclaw<= 2026.2.22-2 (latest published as of February 24, 2026 is 2026.2.22-2)main: 2026.2.23 (released)toolCall.kind and heuristic name matching.read operations were not scoped strongly enough to cwd in all metadata/title forms.toolCall.kind as an authorization source.read auto-approval to cwd-resolved paths.resolvePermissionRequestresolveToolNameForPermissionshouldAutoApproveToolCall12cc754332f9a7c92e158ce7644aa22df79c090463dcd28ae0be2de1c75af09cc81841cebeec068fFound using MCPwner
Thanks @nedlir for reporting.
{
"cwe_ids": [
"CWE-639",
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-27T22:08:36Z",
"nvd_published_at": null,
"severity": "MODERATE"
}