Junglewise Threat Intelligence

CVE-2026-27183: OpenClaw system.run shell approval gating bypass via dispatch-wrapper depth mismatch

CVE-2026-27183 · Severity: low · CVSS 3.1 · Published 2026-03-09

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a JavaScript library that manages execution of system commands with security controls including approval gating for shell invocations. An authorization bypass vulnerability allows an attacker to craft commands with exactly four transparent dispatch wrappers (such as repeated env invocations) to evade the shell approval check in allowlist mode, bypassing expected security gates that should require explicit approval before executing shell payloads.

Technical details

The vulnerability is a logic error (CWE-436/CWE-863) in OpenClaw's system.run dispatch-wrapper handling where the approval classifier and execution planner apply different depth-boundary rules when evaluating shell-wrapper invocations. An attacker can use exactly four transparent wrappers (e.g., env invocations) before /bin/sh -c to cause the approval classifier to stop treating the command as a shell wrapper at the configured boundary, while the execution planner still unwraps through to the shell payload. In security=allowlist mode, this mismatch allows the shell command to execute without triggering the required approval-gate check. The vulnerability requires local privilege context but no user interaction. The fix, released in version 2026.3.7 on March 8, 2026, keeps shell-wrapper classification active at the configured depth boundary and only fails closed beyond it.

Affected products

  • OpenClaw openclaw <= 2026.3.2

Timeline

  • 2026-03-09: disclosed: Advisory GHSA-r6qf-8968-wj9q published
  • 2026-03-07: patched: Fix committed to main branch (2fc95a7cfc1eb9306356510b0251b6d51fb1c0b0)
  • 2026-03-08: patched: npm version 2026.3.7 released with fix

References

Related threats