Executive brief
The @rtk-ai/rtk-rewrite plugin for OpenClaw is vulnerable to a security flaw that allows an attacker to execute unauthorized commands on the underlying server. This occurs because the software fails to properly clean user-provided input before passing it to the system shell. An attacker could exploit this by providing a specially crafted command through an AI agent prompt or a tool-call request, potentially leading to a full system takeover, data theft, or service disruption.
Technical details
An OS command injection vulnerability (CWE-78) exists in the @rtk-ai/rtk-rewrite OpenClaw plugin version 1.0.0. The vulnerability is located in the `tryRewrite` function within `openclaw/index.ts`, where the `execSync` function is used to execute a shell command constructed with a template string. While the code uses `JSON.stringify()` on the input, this method only escapes double quotes and backslashes; it does not neutralize shell metacharacters like `$()` or backticks. Because `execSync` invokes `/bin/sh -c`, the shell performs command substitution even within the double quotes provided by `JSON.stringify`. An attacker who can influence the `exec` tool's command parameter—such as through an LLM prompt or a gateway tool call—can achieve arbitrary code execution. The recommended fix is to migrate from `execSync` to `spawnSync` with `shell: false` and an argument array.
Affected products
- rtk-ai rtk-rewrite 1.0.0
Timeline
- 2026-06-23: advisory: GitHub Advisory GHSA-fqgj-m2gp-mr3q published
- 2026-06-23: disclosed: CVE-2026-55249 published to NVD