CVE-2026-100599
8.8 HIGHpublic exploit availablePublished 2026-09-26 · Updated 2026-09-28
AI risk analysis
- Summary
- The flaw allows an attacker to execute arbitrary processes on a paired node by bypassing the normal approval flow for Google Meet node commands, posing a significant risk to the security and integrity of the system.
- Exploitability
- Exploitation is relatively straightforward given the preconditions of a tool-enabled agent and the Google Meet plugin being enabled. The attacker must have the ability to invoke the googlemeet.chrome command.
- Blast radius
- If exploited, the attacker can impact files, credentials, browser profiles, and availability on the paired node, leading to potential data breaches and system instability.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to OpenClaw 2026.7.1 or later to address the vulnerability.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going through the normal system.run approval flow. In deployments with the Google Meet plugin enabled, a paired Chrome node, and the googlemeet.chrome node command allowed, a tool-enabled agent able to invoke that command can execute attacker-selected processes on the paired node, impacting files, credentials, browser profiles, and availability on that node. The issue is fixed in 2026.7.1; as a workaround, remove googlemeet.chrome from allowed node commands or disable the Google Meet plugin.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100852PoC
- CRITICALCVE-2026-100896PoC
- CRITICALCVE-2026-101001PoC
- CRITICALCVE-2026-101072PoC
- CRITICALCVE-2026-101075PoC
- CRITICALCVE-2026-101076PoC
- CRITICALCVE-2026-102240PoC
- CRITICALCVE-2026-102911PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.