Agentic Consent Bypass: LLM Agent Can Silently Disable Exec Approval via config.patch
openclaw (npm)2026.3.31<=2026.3.24>= 2026.3.28v2026.3.2876411b2afc4ae721e36c12e0ea24fd23e2fed61e — 2026-03-27T09:42:15ZOpenClaw thanks @YLChen-007 for reporting.
{
"severity": "HIGH",
"cwe_ids": [
"CWE-285"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-03T03:03:18Z",
"nvd_published_at": null
}