PT-2026-25107 · Npm · Openclaw

Published

2026-03-02

·

Updated

2026-03-02

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Summary

On Windows ACPX paths, wrapper resolution for .cmd/.bat could fall back to shell execution in ways that allowed cwd influence to alter execution behavior.

Impact

In affected Windows ACPX configurations, this could enable command execution integrity loss through cwd-influenced wrapper resolution.

Fix

Wrapper resolution now prefers explicit PATH/PATHEXT entrypoint resolution and unwrapped Node/EXE execution, with strict fail-closed handling enabled by default for unresolvable wrapper cases.

Affected and Patched Versions

  • Affected: >= 2026.2.26, < 2026.3.1
  • Patched: 2026.3.1

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-6F6J-WX9W-FF4J

Affected Products

Openclaw