PT-2026-26225 · Openclaw · Openclaw
Tdjackey
·
Publicado
2026-02-23
·
Atualizado
2026-04-01
·
CVE-2026-28460
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.22
Description
The software contains an allowlist bypass issue in the
system.run function. This allows attackers to execute commands not included in the allowlist by utilizing shell line-continuation characters to split command substitution. Specifically, injecting $ followed by a newline and an opening parenthesis inside double quotes bypasses security analysis, causing the shell to interpret the line continuation as executable command substitution, circumventing approval boundaries. The issue affects deployments using tools.exec.security=allowlist with ask=on-miss or ask=off.Recommendations
Upgrade to version 2026.2.22 or newer when it is published.
As a temporary mitigation, set
tools.exec.ask=always or tools.exec.security=deny.Correção
Incorrect Authorization
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openclaw