Junglewise Threat Intelligence

CVE-2026-29608: OpenClaw Node system.run approval hardening wrapper semantic drift

CVE-2026-29608 · Severity: low · CVSS 3.1 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Node.js system utility library that provides approval workflows for executing system commands. In version 2026.3.1, a flaw in the approval hardening mechanism allows an attacker to execute unintended local scripts by manipulating command arguments, bypassing the operator's visual approval. An attacker with local access and ability to place a file in the working directory could execute arbitrary scripts that differ from what was approved.

Technical details

The vulnerability is an argument injection flaw (CWE-88) in the node-host approval hardening for system.run. The root cause lies in src/node-host/invoke-system-run-plan.ts, which rewrites argv[0] to the resolved executable path. When wrapper resolution unwraps dispatch wrappers, a command like ['env','sh','-c','echo SAFE'] resolves to /bin/sh, resulting in argv becoming ['/bin/sh','sh','-c','echo SAFE']. The /bin/sh binary interprets the extra positional argument 'sh' as a script path, enabling execution of a local ./sh file from the approved working directory instead of the intended payload. Exploitation requires: local access, ability to influence wrapper argv and place a file in the approved working directory, and operator approval for the displayed command. The vulnerability breaks approval integrity by allowing executed behavior to diverge from operator-visible command text. A fix was released in version 2026.3.2.

Affected products

  • OpenClaw openclaw 2026.3.1; fixed in 2026.3.2

Timeline

  • 2026-03-03: disclosed: GHSA-h3rm-6x7g-882f published
  • 2026-03-03: patched: Fix released in openclaw 2026.3.2

References

Related threats