Junglewise Threat Intelligence

CVE-2026-55249: rtk-ai rtk-rewrite OS command injection in OpenClaw plugin

CVE-2026-55249 · Severity: medium · CVSS 6.3 · Published 2026-06-23

Executive brief

The @rtk-ai/rtk-rewrite plugin for OpenClaw is vulnerable to a security flaw that allows an attacker to execute unauthorized commands on the underlying server. This occurs because the software fails to properly clean user-provided input before passing it to the system shell. An attacker could exploit this by providing a specially crafted command through an AI agent prompt or a tool-call request, potentially leading to a full system takeover, data theft, or service disruption.

Technical details

An OS command injection vulnerability (CWE-78) exists in the @rtk-ai/rtk-rewrite OpenClaw plugin version 1.0.0. The vulnerability is located in the `tryRewrite` function within `openclaw/index.ts`, where the `execSync` function is used to execute a shell command constructed with a template string. While the code uses `JSON.stringify()` on the input, this method only escapes double quotes and backslashes; it does not neutralize shell metacharacters like `$()` or backticks. Because `execSync` invokes `/bin/sh -c`, the shell performs command substitution even within the double quotes provided by `JSON.stringify`. An attacker who can influence the `exec` tool's command parameter—such as through an LLM prompt or a gateway tool call—can achieve arbitrary code execution. The recommended fix is to migrate from `execSync` to `spawnSync` with `shell: false` and an argument array.

Affected products

  • rtk-ai rtk-rewrite 1.0.0

Timeline

  • 2026-06-23: advisory: GitHub Advisory GHSA-fqgj-m2gp-mr3q published
  • 2026-06-23: disclosed: CVE-2026-55249 published to NVD

References