Executive brief
OpenClaw is a gateway system used to control and manage command execution by requiring user approval before running programs. The vulnerability allows an attacker with local access and basic privileges to bypass the approval mechanism by exploiting how the system handles shell script wrappers, enabling unauthorized execution of different programs that would normally require separate approval.
Technical details
The vulnerability is an authorization bypass (CWE-285) in OpenClaw's gateway exec allowlist mechanism. The root cause is that the allow-always persistence feature failed to unwrap /usr/bin/script wrappers and similar shell script execution wrappers before storing trust decisions. An attacker with local user access can approve a command through a wrapper binary, then reconfigure the wrapper to execute a different underlying program—the stored approval would persist and allow the new program to execute without additional authorization. The affected components are src/infra/dispatch-wrapper-resolution.ts and src/infra/exec-wrapper-resolution.ts. The attack requires local access (AV:L), low privilege (PR:L), and user interaction to trigger initial approval (UI:R). Patches are available in version 2026.3.28 and later.
Affected products
- OpenClaw OpenClaw <= 2026.3.24
Timeline
- 2026-03-31: disclosed
- 2026-03-27: patched: Fix committed on 2026-03-27; patched version 2026.3.28 released
- 2026-03-29: other: Advisory published on GitHub