Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated.ts. This manipulation causes improper privilege management. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management | |
| First Time appeared |
Mf-yang
Mf-yang openclaw-cn |
|
| Weaknesses | CWE-266 CWE-269 |
|
| CPEs | cpe:2.3:a:mf-yang:openclaw-cn:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mf-yang
Mf-yang openclaw-cn |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-06T14:56:29.496Z
Reserved: 2026-08-05T20:03:56.712Z
Link: CVE-2026-19007
Updated: 2026-08-06T14:56:23.698Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T07:45:17Z