← Back to search

CVE-2026-100599

8.8 HIGHpublic exploit available

Published 2026-09-26 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows an attacker to execute arbitrary processes on a paired node by bypassing the normal approval flow for Google Meet node commands, posing a significant risk to the security and integrity of the system.
Exploitability
Exploitation is relatively straightforward given the preconditions of a tool-enabled agent and the Google Meet plugin being enabled. The attacker must have the ability to invoke the googlemeet.chrome command.
Blast radius
If exploited, the attacker can impact files, credentials, browser profiles, and availability on the paired node, leading to potential data breaches and system instability.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to OpenClaw 2026.7.1 or later to address the vulnerability.
rcewebgooglemeetnodevulnerability

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going through the normal system.run approval flow. In deployments with the Google Meet plugin enabled, a paired Chrome node, and the googlemeet.chrome node command allowed, a tool-enabled agent able to invoke that command can execute attacker-selected processes on the paired node, impacting files, credentials, browser profiles, and availability on that node. The issue is fixed in 2026.7.1; as a workaround, remove googlemeet.chrome from allowed node commands or disable the Google Meet plugin.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.