PT-2026-26233 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-19
·
Updated
2026-03-19
·
CVE-2026-31993
CVSS v3.1
4.8
Medium
| AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:L |
OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that allows authenticated operators to bypass exec approval checks. Attackers with operator.write privileges and a paired macOS beta node can craft shell-chain payloads that pass incomplete allowlist validation and execute arbitrary commands on the paired host.
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw