Junglewise Threat Intelligence

CVE-2026-15193: AidanPark openclaw-android OS command injection in JsBridge.kt

CVE-2026-15193 · Severity: medium · CVSS 5.3 · Published 2026-07-09

Executive brief

AidanPark openclaw-android is an application used to run the OpenClaw game engine on Android devices. A security flaw in the application's internal communication bridge allows a malicious actor with local access to execute unauthorized system commands. This could lead to a compromise of the application's data or unauthorized control over the app's runtime environment.

Technical details

An OS command injection vulnerability exists in AidanPark openclaw-android up to version 0.4.0 within the JsBridge.kt file. The application exposes a native JavaScript bridge (window.OpenClaw) to WebView content that includes functions such as runCommand and runCommandAsync. These functions accept caller-controlled strings and pass them directly to a command runner that executes them via 'sh -c' without proper sanitization or allowlisting. A local attacker or malicious JavaScript within the WebView can exploit this to execute arbitrary shell commands in the context of the app's runtime. A pull request (PR #137) has been submitted to address the issue by implementing a command allowlist and using ProcessBuilder.

Affected products

  • AidanPark openclaw-android up to 0.4.0

Timeline

  • 2026-06-08: disclosed: Issue reported on GitHub and fix proposed via pull request.
  • 2026-07-09: advisory: CVE published by VulDB/NVD.

References