PT-2026-26235 · Openclaw+1 · Blobster+2

·

CVE-2026-31995

·

Publicado

2026-02-19

·

Atualizado

2026-03-20

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.1.21 through 2026.2.17
Description The Lobster extension in OpenClaw contains a command injection issue on Windows systems. This occurs due to the fallback mechanism used when spawning processes fails, specifically when shell: true is enabled. Attackers can inject arbitrary commands through arguments provided to the tool, which are then interpreted by cmd.exe. The issue arises when spawn failures trigger shell fallback with shell set to true, allowing attackers to control workflow arguments and execute malicious commands. The Windows shell fallback has been removed in a later version.
Recommendations Update to OpenClaw version 2026.2.19 or later.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05251
CVE-2026-31995
GHSA-8PX5-2GFR-7PH6
GHSA-FG3M-VHRR-8GJ6

Produtos afetados

Blobster
Openclaw
Windows