CVE-2026-19006: mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization
A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Ggateway Exec Approval Flow. The manipulation results in incorrect authorization. The attack may be performed from remote. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19006?
The severity of CVE-2026-19006 is medium, rated at 6.3.
How do I fix CVE-2026-19006?
To fix CVE-2026-19006, you should update the mf-yang openclaw-cn Ggateway Exec Approval Flow to the latest version that addresses this vulnerability.
What component is affected by CVE-2026-19006?
CVE-2026-19006 affects the src/agents/bash-tools.exec.ts file within the mf-yang openclaw-cn Ggateway Exec Approval Flow.
Can CVE-2026-19006 be exploited remotely?
Yes, CVE-2026-19006 can be exploited remotely, allowing unauthorized actions to be performed.
What type of vulnerability is CVE-2026-19006?
CVE-2026-19006 is an authorization vulnerability that results in incorrect authorization in the system.