Executive brief
OpenClaw is a tool used to manage and execute commands on remote systems. A security flaw in the Linux and macOS versions allows users to bypass restrictions on what specific commands or arguments can be run. This could allow an attacker to execute unauthorized commands, potentially leading to data theft or full system compromise.
Technical details
OpenClaw gateways on Linux and macOS fail to validate the 'argPattern' field within the 'exec' allowlist configuration. While the system correctly checks the executable path, it skips the secondary check intended to restrict which arguments are passed to that executable. An attacker with the ability to influence tool-enabled agents can exploit this to run disallowed arguments for sensitive binaries like git, python, or bash. This bypasses the intended security guardrails that should require an approval prompt for non-matching argument patterns. The issue is addressed in version 2026.5.12.
Affected products
- OpenClaw openclaw < 2026.5.12
Timeline
- 2026-05-28: disclosed
- 2026-06-18: advisory
- 2026-05-12: patched: First stable patched version released
References
- https://api.github.com/users/Curly-Haired-Baboon
- https://github.com/Curly-Haired-Baboon
- https://api.github.com/users/Curly-Haired-Baboon/gists%7B/gist_id%7D
- https://api.github.com/users/Curly-Haired-Baboon/repos
- https://avatars.githubusercontent.com/u/227850795?v=4
- https://api.github.com/users/Curly-Haired-Baboon/events%7B/privacy%7D