Junglewise Threat Intelligence

CVE-2026-43530: OpenClaw weakened exec approval binding in busybox and toybox

CVE-2026-43530 · Severity: low · CVSS 3.1 · Published 2026-04-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a tool execution framework that enforces security policies on command execution. The vulnerability allowed attackers to bypass its exec approval mechanism by invoking busybox or toybox with command-execution applets (like awk, find, xargs) that were incorrectly classified as safe interpreters. An attacker operating within the sandbox could run arbitrary commands without explicit approval, weakening the runtime security boundaries. The fix treats these tools as opaque and rejects applet invocations that don't meet strict approval requirements.

Technical details

This is an authorization bypass vulnerability (CWE-863) in OpenClaw's exec safety policy. Busybox and toybox were classified in the INTERPRETER_LIKE_SAFE_BINS set, causing the runtime policy to treat them as always-safe script runners. However, these tools are multi-call binaries with applets—some of which (awk, find, xargs) can execute arbitrary commands. An attacker could invoke busybox awk 'BEGIN{system("command")}' and the policy would approve it because busybox itself was marked safe, even though the awk applet requires explicit authorization. The fix moves busybox and toybox to a new OPAQUE_MUTABLE_SCRIPT_RUNNERS set, which still flags them as mutable but prevents the generic script-operand resolver from binding to a file when an applet name occupies argv[1], causing all applet invocations to be rejected. No authentication or network access is required; the vulnerability affects any caller with execution access.

Affected products

  • OpenClaw openclaw >= 2026.2.23 < 2026.4.12

Timeline

  • 2026-04-17: disclosed
  • 2026-04-12: patched: Fix merged in PR #65713; version 2026.4.12 and later contain the patch
  • 2026-04-13: other: Fix commit 666f48d9b882a8a1415ca53f9567c72499d850c9 authored

References

Related threats