Executive brief
OpenClaw is a tool that enforces security policies on shell command execution through an allowlist feature. An attacker can bypass this security control using shell line-continuation syntax within command substitution, allowing execution of commands that should be restricted. This could result in unauthorized command execution in deployments that rely on the allowlist security mechanism.
Technical details
This is an authorization bypass vulnerability (CWE-863) combined with OS command injection (CWE-78) in OpenClaw's system.run allowlist mode. The vulnerability exists in the shell-wrapper analysis component, which fails to properly parse shell line-continuation characters when used within command substitution. An attacker can split a command substitution as $\\ + newline + ( inside double quotes; the static analysis treats this as an allowlisted command (e.g., /bin/echo), but the shell runtime folds the line continuation and executes the malicious subcommand. The attack requires deployment with tools.exec.security=allowlist mode enabled (with ask=on-miss or ask=off). A fix is available in version 2026.2.22 or newer; temporary mitigation involves setting tools.exec.ask=always or tools.exec.security=deny.
Affected products
- OpenClaw OpenClaw <=2026.2.21-2
Timeline
- 2026-03-03: disclosed
- 2026-03-03: patched: Patched version 2026.2.22 planned