PT-2026-23545 · Openclaw · Openclaw

Petr Simecek

·

Published

2026-02-17

·

Updated

2026-03-17

·

CVE-2026-28470

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.2
Description The software contains a flaw in its exec approvals allowlist, which can be bypassed when command substitution syntax is used. Specifically, attackers can execute arbitrary commands by injecting command substitution syntax, such as $() or backticks, within double-quoted strings. This bypasses the intended allowlist protection. The issue only affects installations where the exec approvals allowlist feature is explicitly enabled.
Recommendations Update to version 2026.2.2 or later. Reject unescaped $() and backticks inside double quotes during allowlist analysis.

Fix

Argument Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28470
GHSA-3HCM-GGVF-RCH5

Affected Products

Openclaw