CVE-2026-100599
Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.
- Condivisione
- PUBLIC-OSINT
- Confidenza
- 100
- Fonte
- The CVE Program
- Aggiornata
- 26/09/2026 08:14
Descrizione
OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going through the normal system.run approval flow. In deployments with the Google Meet plugin enabled, a paired Chrome node, and the googlemeet.chrome node command allowed, a tool-enabled agent able to invoke that command can execute attacker-selected processes on the paired node, impacting files, credentials, browser profiles, and availability on that node. The issue is fixed in 2026.7.1; as a workaround, remove googlemeet.chrome from allowed node commands or disable the Google Meet plugin.
Alias e classificazioni
Dettagli tecnici minimizzati
Nessun dato grezzo- cisa kev
- False
- cvss score
- 8.8
- cvss vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- cvss severity
- HIGH
Riferimenti pubblici
- VulnCheck Advisory: OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome
https://www.vulncheck.com/advisories/openclaw-2026.5.1-before-2026.7.1-remote-code-execution-via-googlemeet-chrome - GitHub Security Advisory (GHSA-224w-vfr9-h35c)
https://github.com/openclaw/openclaw/security/advisories/GHSA-224w-vfr9-h35c
Catalogo Intel
La vulnerabilità è presente anche nel catalogo editoriale EudorIA.
Apri analisi EudorIALa presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.