PT-2026-6548 · Openclaw · Openclaw

·

CVE-2026-25593

·

Published

2026-02-04

·

Updated

2026-03-11

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.1.20
Description An unauthenticated local client could leverage the Gateway WebSocket API to modify configuration settings through the config.apply function. Specifically, the ability to set unsafe cliPath values, which are subsequently used for command discovery, allows for command injection with the privileges of the gateway user. The config.apply function accepted raw JSON and wrote it to disk after schema validation. The cliPath values were not restricted to safe executable names or paths. Command discovery utilized a shell invocation when resolving executables.
Recommendations Upgrade to version 2026.1.20 or later. If an immediate upgrade is not possible, enable gateway.auth and avoid using custom cliPath values.

Exploit

Fix

Missing Authentication

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25593
GHSA-G55J-C2V4-PJCG

Affected Products

Openclaw