PT-2026-26232 · Openclaw · Openclaw
Tdjackey
·
Published
2026-02-24
·
Updated
2026-03-20
·
CVE-2026-31992
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.23
OpenClaw versions 2026.2.22 and earlier
Description
The software contains an allowlist bypass issue in
system.run guardrails. This allows authenticated operators to execute unintended commands. Specifically, when /usr/bin/env is allowlisted, attackers can use env -S to bypass policy analysis and execute shell wrapper payloads at runtime. The issue weakens expected safety behavior and can enable unintended command execution when untrusted content influences tool input. The vulnerability exists due to a parity issue between allowlist and runtime execution semantics for shell wrappers. The vulnerable component is the allowlist mode within the system.run function.Recommendations
OpenClaw versions prior to 2026.2.23 should be updated to version 2026.2.23 or later.
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw