Executive brief
OpenClaw, a developer tool for managing execution environments, contains a security flaw in how it filters commands. An attacker with low-level access could bypass security restrictions to execute unauthorized commands or persist malicious actions on the host system. This could lead to a full system compromise, unauthorized data access, or service disruption.
Technical details
OpenClaw versions prior to 2026.6.6 are vulnerable to OS command injection and improper input validation (CWE-78, CWE-184) within the host execution environment filtering logic. The vulnerability stems from an incomplete list of disallowed inputs that fails to block the 'git-remote-ext' (Git ext transport) protocol. A remote attacker with low privileges can provide a specially crafted input path or command that abuses this transport mechanism to execute arbitrary code or persist actions beyond their intended authorization level. The exploit requires the affected feature to be enabled and reachable by the caller. A fix is available in version 2026.6.6.
Affected products
- OpenClaw OpenClaw < 2026.6.6
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-13: disclosed: NVD publication date