---
id: GHSA-r7vv-6763-m739
title: 'Duplicate Advisory: Skill-command dispatch could skip before-tool-call hooks'
summary: 'Duplicate Advisory: Skill-command dispatch could skip before-tool-call hooks'
severity: low
cvss: 4.3
cwe:
  - CWE-693
vendor: openclaw
product: openclaw
ecosystem: npm
affected:
  - openclaw <= 2026.5.5
published: '2026-06-16'
updated: '2026-06-18'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-r7vv-6763-m739'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-68xw-r643-9p5w
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53845'
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-skill-command-dispatch-hook-bypass-via-before-tool-call-hook-skipping
  - url: 'https://github.com/advisories/GHSA-r7vv-6763-m739'
tags:
  - ghsa
  - npm
ingestedAt: '2026-06-29T14:31:47.500Z'
---

## Overview

## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-68xw-r643-9p5w. This link is maintained to preserve external references.

## Original Description
OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch path skip before-tool-call hook coverage. Attackers can exploit this by sending skill commands through the vulnerable dispatch path to bypass hook-based auditing and policy enforcement mechanisms.

## Affected packages

- `openclaw <= 2026.5.5`

## Remediation

Refer to the advisory for the patched release.
