Executive brief
OpenClaw is a JavaScript gateway framework that exposes configuration APIs via WebSocket. An unauthenticated local attacker can inject arbitrary shell commands through the config.apply API by setting unsafe executable paths, which are then executed with the gateway process privileges. This allows complete system compromise for any local user or process on the same machine.
Technical details
The vulnerability is an OS command injection (CWE-78) combined with missing authentication (CWE-306) and improper input validation (CWE-20). The config.apply WebSocket endpoint accepts raw JSON without requiring authentication and writes configuration to disk after only schema validation. The cliPath configuration parameter is not constrained to safe paths and is later used in shell command execution during command discovery, allowing an attacker to inject shell metacharacters or absolute paths to arbitrary executables. An unauthenticated local process can exploit this to execute arbitrary commands as the gateway user. The fix was released in version 2026.1.20. Mitigations include enabling gateway.auth and avoiding custom cliPath values.
Affected products
- OpenClaw OpenClaw < 2026.1.20
Timeline
- 2026-02-04: disclosed
- 2026-01-20: patched: version 2026.1.20 released