PT-2026-26233 · Openclaw · Openclaw
Tdjackey
·
Published
2026-02-21
·
Updated
2026-03-20
·
CVE-2026-31993
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:H/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.22
Description
The OpenClaw macOS companion app contains a flaw in how it parses allowlists, potentially allowing authenticated operators to bypass execution approval checks. Specifically, attackers with
operator.write privileges and a paired macOS beta node can create shell-chain payloads that circumvent incomplete allowlist validation, leading to arbitrary command execution on the paired host. This requires exec approvals to be set to security=allowlist and ask=on-miss. The issue stems from unsafe shell-substitution parsing in allowlist mode. The fix involves hardening macOS allowlist resolution by evaluating shell chains per segment and failing closed on unsafe parsing.Recommendations
OpenClaw versions prior to 2026.2.22 should be updated.
Fix
Improper Authorization
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw