CVE-2026-53814
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
描述
### Summary OpenClaw hook ingress can start automated agent runs using a configured hook token. In affected releases, a hook-triggered run could select a bundled CLI backend that received owner-scoped MCP loopback authority instead of a scope appropriate for hook ingress. This issue affects the boundary between hook-token automation and owner-only MCP tools. It does not affect deployments with hooks disabled. ### Affected configurations This affects deployments where hooks are enabled, `/hooks/agent` is reachable with a valid hook token, and a bundled CLI backend can be selected for the hook-triggered run. ### Impact A caller with the hook token could cause the spawned CLI runtime to see or call MCP tools that should have been owner-only. The practical impact depends on which MCP tools are available; the reported proof used persistent cron state as a representative owner-only action. ### Patched Versions The first stable patched version is `2026.5.20`. Fixed in the `2026.5.20` stable release. ### Mitigations Upgrade to `openclaw@2026.5.20` or later. Keep hook tokens secret, restrict network access to hook endpoints, and disable hooks when they are not needed.
如何修補 CVE-2026-53814
要修補 CVE-2026-53814,請將受影響套件升級到下列已修補版本。
- —升級至 2026.5.20 或更新版本
CVE-2026-53814 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2026.5.20
CVSS 分數
| 來源 | 版本 | 嚴重程度 |
|---|