PT-2026-26239 · Microsoft+1 · Windows+1
CVSS v4.0
9.3
Crítica
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.2.26 through 2026.3.1
Description
OpenClaw on Windows contains a current working directory injection flaw in wrapper resolution for .cmd/.bat files. This allows attackers to influence execution behavior through current working directory (cwd) manipulation. Improper shell execution fallback mechanisms can lead to command execution integrity loss by controlling the cwd during wrapper resolution. The issue affects Windows ACPX paths where wrapper resolution for
.cmd/.bat files could fall back to shell execution, enabling cwd influence to alter execution behavior.Recommendations
OpenClaw versions 2026.2.26 through 2026.3.1 should be updated to version 2026.3.1.
Exploit
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openclaw
Windows