PT-2026-26232 · Openclaw · Openclaw

Tdjackey

·

Published

2026-02-24

·

Updated

2026-03-20

·

CVE-2026-31992

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.23 OpenClaw versions 2026.2.22 and earlier
Description The software contains an allowlist bypass issue in system.run guardrails. This allows authenticated operators to execute unintended commands. Specifically, when /usr/bin/env is allowlisted, attackers can use env -S to bypass policy analysis and execute shell wrapper payloads at runtime. The issue weakens expected safety behavior and can enable unintended command execution when untrusted content influences tool input. The vulnerability exists due to a parity issue between allowlist and runtime execution semantics for shell wrappers. The vulnerable component is the allowlist mode within the system.run function.
Recommendations OpenClaw versions prior to 2026.2.23 should be updated to version 2026.2.23 or later.

Fix

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

BDU:2026-05010
CVE-2026-31992
GHSA-48WF-G7CP-GR3M
GHSA-X742-88JJ-7HV9

Affected Products

Openclaw