PT-2026-5722 · Openclaw · Openclaw

Berkdedekarginoglu

·

Published

2026-02-02

·

Updated

2026-03-18

·

CVE-2026-24763

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.1.29
Description OpenClaw, formerly Clawdbot, a personal AI assistant, had a command injection issue in its Docker sandbox execution mechanism. This was due to unsafe handling of the PATH environment variable when building shell commands. An authenticated user who could control environment variables could influence command execution within the container. The issue could lead to the execution of unintended commands inside the container, access to the container filesystem and environment variables, exposure of sensitive data, and an increased risk in misconfigured or privileged container environments.
Recommendations Update to version 2026.1.29.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-05649
CVE-2026-24763
GHSA-MC68-Q9JW-2H3V

Affected Products

Openclaw