GHSA-gv46-4xfq-jv58 · Severity: critical · Ecosystem: npm — OpenClaw Vulnerable to Remote Code Execution via Node Invoke Approval Bypass in Gateway
OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing authenticated clients to bypass exec approval gating for system.run commands. Attackers with valid gateway credentials can inject approval control fields to execute arbitrary commands on connected node hosts, potentially compromising developer workstations and CI runners.
Conclusion & alert: CVE-2026-28466 is rated Moderate Risk (43.1/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.05%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-12 | 0.04% | 0.05% | +0.01% |
| 2 | 2026-04-21 | 0.08% | 0.04% | -0.03% |
| 3 | 2026-03-06 | — | 0.08% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.4 | 4.0 | CRITICAL |
|
— | — | [email protected] |
| 9.9 | 3.1 | CRITICAL |
|
3.1 | 6.0 | [email protected] |
GHSA-gv46-4xfq-jv58 · Severity: critical · Ecosystem: npm — OpenClaw Vulnerable to Remote Code Execution via Node Invoke Approval Bypass in Gateway