๐Ÿ” CVE Alert

CVE-2026-19007

MEDIUM 6.3

mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated.ts. This manipulation causes improper privilege management. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-269 CWE-266
Vendor mf-yang
Product openclaw-cn
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for mf-yang openclaw-cn

Be the first to know when new medium vulnerabilities affecting mf-yang openclaw-cn are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

mf-yang / openclaw-cn
0.2.0 0.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/386390 vuldb.com: https://vuldb.com/vuln/386390/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19007 vuldb.com: https://vuldb.com/submit/862643 github.com: https://github.com/mf-yang/openclaw-cn/issues/564 github.com: https://github.com/mf-yang/openclaw-cn/

Credits

๐Ÿ” TrumpChen (VulDB User) VulDB CNA Team