Executive brief
OpenClaw is a personal AI assistant and automation platform. A vulnerability in how it processes shell commands allows an attacker to bypass security checks by using specific combinations of command-line options. If exploited, an attacker could execute unauthorized commands on the host system, potentially leading to full system compromise or data theft.
Technical details
A Time-of-check Time-of-use (TOCTOU) vulnerability exists in OpenClaw's execution revalidation logic (CWE-367). The root cause is a discrepancy between how combined POSIX shell flags (e.g., -xc) are parsed during the approval phase versus the execution phase. An authenticated attacker with low privileges can provide a command request that appears benign during allowlist validation but executes malicious inline shell content at runtime. This bypasses intended security boundaries and allowlists. The issue is fixed in version 2026.5.12.
Affected products
- OpenClaw openclaw <= 2026.5.7
Timeline
- 2026-05-28: disclosed: Initial disclosure by reporter
- 2026-06-11: advisory: NVD publication date
- 2026-07-02: advisory: GitHub Advisory reviewed and updated