PT-2026-26237 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-02
·
Updated
2026-03-19
·
CVE-2026-31997
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.1
Description
OpenClaw fails to properly validate executable identity for non-path-like
argv[0] tokens during system.run approvals. This allows for post-approval executable rebind attacks, where an attacker can modify the PATH resolution after approval to execute a different binary than the operator initially approved, potentially leading to arbitrary command execution. The system.run approvals did not pin executable identity, and path-token commands were not pinned to canonical executable identity (realpath) across approval and execution.Recommendations
Versions prior to 2026.3.1 should be updated to version 2026.3.1 or later.
Fix
Untrusted Search Path
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw