Junglewise Threat Intelligence

CVE-2026-35666: OpenClaw allowlist bypass in system.run approvals

CVE-2026-35666 · Severity: high · CVSS 8.8 · Published 2026-04-10

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, an AI assistant platform, contains a security flaw in how it manages authorized commands. An attacker can bypass the system's security allowlist by wrapping unauthorized commands inside the 'time' utility, which the system fails to inspect properly. This could allow an unauthorized user to execute arbitrary commands on the underlying system, potentially leading to full data exposure or system takeover.

Technical details

A vulnerability in OpenClaw (npm package) exists where the 'system.run' execution approval logic fails to correctly unwrap the '/usr/bin/time' utility. Because the system binds 'allow-always' approvals to the outer wrapper rather than the intended inner executable, an attacker can use an unregistered time wrapper to reuse existing approval states for unauthorized commands. This is a bypass of the command allowlist (CWE-863/CWE-706). Exploitation requires low privileges and network access but no user interaction. The issue is fixed in version 2026.3.22 by ensuring the dispatch-wrapper resolution logic unwraps the time utility and binds approvals to the actual inner executable.

Affected products

  • OpenClaw openclaw < 2026.3.22

Timeline

  • 2026-03-24: disclosed
  • 2026-03-24: patched: Fix shipped in v2026.3.22
  • 2026-03-26: advisory: GitHub Advisory published
  • 2026-04-10: other: NVD published

References

Related threats