PT-2026-26007 · Openclaw+2 · Openclaw+2

Jisung

·

Publicado

2026-02-24

·

Atualizado

2026-03-19

·

CVE-2026-22175

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.23
Description OpenClaw contains a flaw in allowlist mode where 'allow-always' grants can be bypassed through unrecognized multiplexer shell wrappers, such as busybox sh -c and toybox sh -c commands. This allows attackers to invoke arbitrary payloads under the same multiplexer wrapper, satisfying stored allowlist rules and circumventing intended execution restrictions. The issue arises because wrapper analysis incorrectly treated invocations of busybox and toybox as non-wrapper commands, persisting the wrapper binary path instead of the inner executable. This allowed subsequent arbitrary payloads to satisfy the stored allowlist rule. The fix improves wrapper detection and persistence behavior, ensuring approvals bind to the intended inner executables and fail closed when unwrap safety is uncertain.
Recommendations Update OpenClaw to version 2026.2.23 or later.

Correção

Incomplete List of Disallowed Inputs

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05063
CVE-2026-22175
GHSA-GWQP-86Q6-W47G

Produtos afetados

Openclaw
Busybox
Toybox