PT-2026-26734 · Openclaw · Openclaw
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.24
Description
The software contains a command injection issue in the
system.run shell-wrapper. This allows attackers to execute hidden commands by injecting positional argv carriers after inline shell payloads. Attackers can craft misleading approval text while executing arbitrary commands through trailing positional arguments, bypassing display context validation.Recommendations
Update OpenClaw to version 2026.2.24 or later.
Exploit
Correção
Incorrect Authorization
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openclaw