
OpenClaw shipped a whole bundle of CVEs today. One of them, CVE-2026-100599, let the Google Meet integration skip the approval path and run commands on your paired node. CVSS 8.8, fixed in 2026.7.1. Update tonight.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going through the normal system.run approval flow. In deployments with the Google Meet plugin enabled, a paired Chrome node, and the googlemeet.chrome node command allowed, a tool-enabled agent able to invoke that command can execute attacker-selected processes on the paired node, impacting files, credentials, browser profiles, and availability on that node. The issue is fixed in 2026.7.1; as a workaround, remove googlemeet.chrome from allowed node commands or disable the Google Meet plugin.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

OpenClaw shipped a whole bundle of CVEs today. One of them, CVE-2026-100599, let the Google Meet integration skip the approval path and run commands on your paired node. CVSS 8.8, fixed in 2026.7.1. Update tonight.

🚨 OpenClaw’da 4 yeni High seviye güvenlik açığı OpenClaw'ın 2026.7.1 öncesi sürümlerini etkileyen 4 yeni CVE yayınlandı: 🔸 CVE-2026-100599 | CVSS 8.8 Google Meet node komutları üzerinden approval mekanizmasının bypass edilmesi ve bağlı node üzerinde kod çalıştırılması (RCE). 🔸 CVE-2026-100596 | CVSS 8.8 MCP yapılandırması üzerinden authorization bypass. Kötü amaçlı stdio komutu yapılandırmaya eklenerek kalıcı kod çalıştırma mümkün olabiliyor. 🔸 CVE-2026-100588 | CVSS 8.3 node.invoke üzerinden yetkilendirme kontrolünün aşılması ve bağlı browser node üzerinde yetkisiz işlemler gerçekleştirilmesi. 🔸 CVE-2026-100589 | CVSS 8.8 Sandbox kısıtlamalarının browser üzerinden aşılmasıyla host browser/node kontrolüne erişim sağlanabilmesi. 🛡️ Etkilenen sürümler: OpenClaw < 2026.7.1 ✅ Çözüm: OpenClaw 2026.7.1 veya üzeri sürüme güncelleyin. Özellikle CVE-2026-100599 ve CVE-2026-100596, agent'ın yetkileri üzerinden host üzerinde kod çalıştırma açısından dikkat çekiyor.