Junglewise Threat Intelligence

CVE-2026-31992: OpenClaw allowlist exec-guard bypass via env -S

CVE-2026-31992 · Severity: medium · CVSS 4 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI automation platform that can execute system commands under controlled safety policies. In allowlist mode, administrators define which commands are permitted for execution. A vulnerability in versions before 2026.2.23 allows authenticated operators to bypass these safety controls by using the `env -S` flag to reinterpret how commands are executed, enabling them to run commands that should have been blocked. This weakens the trusted-operator safety model and could allow unintended execution of shell commands when untrusted content influences the tool inputs.

Technical details

This is a policy-analysis/runtime-execution mismatch vulnerability in OpenClaw's allowlist validation for the `system.run` guardrails. The vulnerability exists in how `env -S` (split-string flag) is handled during command approval analysis versus runtime execution. When `/usr/bin/env` is allowlisted, the static policy analyzer treats `env -S 'sh -c command'` as an allowed non-wrapper argv, but the runtime still interprets and executes the `sh -c` portion as shell-wrapper semantics. An authenticated Gateway caller (trusted operator by design) can exploit this to execute commands beyond their allowlist scope. The fix, released in version 2026.2.23, enforces canonical wrapper execution plans across both allowlist analysis and runtime execution phases, hardens `env` wrapper semantic detection, and rejects unknown short safe-bin flags to prevent interpretation mismatches. Two commits address the core issue (a1c4bf0) and add regression tests (3f923e8).

Affected products

  • openclaw openclaw <=2026.2.22-2

Timeline

  • 2026-03-03: disclosed: Advisory published
  • 2026-02-24: patched: Security fix committed; patched versions >= 2026.2.23 released

References