A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated.ts. This manipulation causes improper privilege management. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated.ts. This manipulation causes improper privilege management. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management | |
| First Time appeared |
Mf-yang
Mf-yang openclaw-cn |
|
| Weaknesses | CWE-266 CWE-269 |
|
| CPEs | cpe:2.3:a:mf-yang:openclaw-cn:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mf-yang
Mf-yang openclaw-cn |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-06T06:15:08.258Z
Reserved: 2026-08-05T20:03:56.712Z
Link: CVE-2026-19007
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T07:45:17Z