Executive brief
OpenClaw's system.run function is a tool that executes shell commands on behalf of users. The vulnerability allows an authenticated caller to inject environment variables (SHELLOPTS and PS4) that bypass the system's allowlist of permitted commands, enabling execution of arbitrary shell commands. This breaks the security model intended to restrict what commands can be run, potentially leading to unauthorized access to system resources and data.
Technical details
The vulnerability is a shell environment injection flaw (CWE-78, CWE-15) in OpenClaw's system.run function. The root cause is incomplete environment variable sanitization: the code blocked startup-file vectors like BASH_ENV and ENV, but failed to block SHELLOPTS and PS4. When shell wrappers (bash|sh|zsh with -c or -lc flags) are invoked, request-scoped environment overrides are passed through, and bash evaluates PS4 under xtrace mode, enabling command substitution. Exploitation requires the attacker to be an authenticated Gateway caller who can invoke system.run with request-scoped environment variables—a precondition satisfied in multi-operator scenarios. The fix blocks SHELLOPTS and PS4 in host exec sanitizers and restricts shell-wrapper request environment overrides to an explicit allowlist (TERM, LANG, LC_*, COLORTERM, NO_COLOR, FORCE_COLOR). The patched version is 2026.2.22 or later.
Affected products
- OpenClaw openclaw <= 2026.2.21-2
Timeline
- 2026-03-03: disclosed: Advisory published (GHSA-2fgq-7j6h-9rm4)
- 2026-02-22: patched: Security fix committed (e80c803fa887f9699ad87a9e906ab5c1ff85bd9a); planned release 2026.2.22
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-2fgq-7j6h-9rm4
- https://github.com/openclaw/openclaw/commit/e80c803fa887f9699ad87a9e906ab5c1ff85bd9a
- https://github.com/openclaw/openclaw
- https://www.vulncheck.com/advisories/openclaw-remote-code-execution-via-shellopts-ps4-environment-injection-in-system-run