PT-2026-26225 · Openclaw · Openclaw

Tdjackey

·

Publicado

2026-02-23

·

Atualizado

2026-04-01

·

CVE-2026-28460

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.22
Description The software contains an allowlist bypass issue in the system.run function. This allows attackers to execute commands not included in the allowlist by utilizing shell line-continuation characters to split command substitution. Specifically, injecting $ followed by a newline and an opening parenthesis inside double quotes bypasses security analysis, causing the shell to interpret the line continuation as executable command substitution, circumventing approval boundaries. The issue affects deployments using tools.exec.security=allowlist with ask=on-miss or ask=off.
Recommendations Upgrade to version 2026.2.22 or newer when it is published. As a temporary mitigation, set tools.exec.ask=always or tools.exec.security=deny.

Correção

Incorrect Authorization

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05018
CVE-2026-28460
GHSA-9868-VXMX-W862
GHSA-XRGV-34CC-Q765

Produtos afetados

Openclaw