Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-26320

22
FAUCET Score

CVE-2026-26320 describes a social engineering vulnerability in OpenClaw macOS desktop client versions 2026.2.6 through 2026.2.13. An attacker could craft a malicious deep link using the openclaw://agent scheme, padding the message with whitespace to hide a harmful payload beyond the visible confirmation dialog. If a user approves this misrepresented prompt, the agent could execute arbitrary commands depending on their configurations. This vulnerability has a CVSS score of 6.5 (Medium) due to its network attack vector, low attack complexity, and high impact on integrity, requiring user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog. The issue is fixed in version 2026.2.14.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2026.2.6, < 2026.2.14CPE matchmatch criteria
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

7.1HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
34.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 36th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: openclawFixed in: 2026.2.14

Vendor Advisories (1)

npmGHSA-7q2j-c4q5-rm27high

OpenClaw macOS deep link confirmation truncation can conceal executed agent message

Feb 17, 2026

References

github.com / openclaw/openclaw/commit/28d9dd7a772501ccc3f71457b4adfee79084fe6f
Patch
github.com / openclaw/openclaw/releases/tag/v2026.2.14
ProductRelease Notes
github.com / openclaw/openclaw/security/advisories/GHSA-7q2j-c4q5-rm27
MitigationPatchVendor Advisory