PT-2026-26239 · Microsoft+1 · Windows+1

·

CVE-2026-31999

·

Publicado

2026-03-02

·

Atualizado

2026-03-22

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.2.26 through 2026.3.1
Description OpenClaw on Windows contains a current working directory injection flaw in wrapper resolution for .cmd/.bat files. This allows attackers to influence execution behavior through current working directory (cwd) manipulation. Improper shell execution fallback mechanisms can lead to command execution integrity loss by controlling the cwd during wrapper resolution. The issue affects Windows ACPX paths where wrapper resolution for .cmd/.bat files could fall back to shell execution, enabling cwd influence to alter execution behavior.
Recommendations OpenClaw versions 2026.2.26 through 2026.3.1 should be updated to version 2026.3.1.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05042
CVE-2026-31999
GHSA-6F6J-WX9W-FF4J
GHSA-H36M-2VH5-X699

Produtos afetados

Openclaw
Windows