PT-2026-26239 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-19

·

Updated

2026-03-19

·

CVE-2026-31999

CVSS v3.1

6.3

Medium

AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in wrapper resolution for .cmd/.bat files that allows attackers to influence execution behavior through cwd manipulation. Remote attackers can exploit improper shell execution fallback mechanisms to achieve command execution integrity loss by controlling the current working directory during wrapper resolution.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-31999

Affected Products

Openclaw