Boletines de Vulnerabilidades |
CVE-2026-31993 |
|
| Software afectado | MACOS |
| OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that allows authenticated operators to bypass exec approval checks. Attackers with operator.write privileges and a paired macOS beta node can craft shell-chain payloads that pass incomplete allowlist validation and execute arbitrary commands on the paired host. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-31993 | |














