Junglewise Threat Intelligence

CVE-2026-41380: OpenClaw gateway exec allow-always over-trusts positional carrier executables

CVE-2026-41380 · Severity: high · CVSS 7.3 · Published 2026-04-01

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an open-source execution approval and allowlisting tool used to control which commands and scripts can run on systems. A flaw in its approval mechanism allows a single approval decision to inadvertently whitelist unintended wrapper executables, potentially permitting attackers with local access to execute broader commands than originally authorized.

Technical details

The vulnerability (CWE-863: Incorrect Authorization) exists in src/infra/exec-approvals-allowlist.ts, where the allow-always persistence mechanism fails to distinguish between wrapper carrier executables and the actual invoked command targets when commands are routed through dispatch wrappers. An attacker with local privileges and the ability to trigger user interaction can exploit this to cause a one-time approval to create a broader allowlist entry than intended. Attack preconditions include local access (AV:L), low attack complexity (AC:L), low privileges required (PR:L), and required user interaction (UI:R). The impact is high across confidentiality, integrity, and availability. Patched versions 2026.3.28 and later contain the fix via commit 9ec44fad39.

Affected products

  • OpenClaw openclaw <= 2026.3.24

Timeline

  • 2026-04-01: disclosed: Advisory published
  • 2026-03-28: patched: Version 2026.3.28 released with fix

References

Related threats