Executive brief
OpenClaw is a security-focused command execution tool used to enforce policies around which commands can be run. A policy enforcement mismatch allows an attacker who can inject untrusted commands (e.g., through prompt injection) to bypass the allowed-commands allowlist and execute arbitrary commands that should have been blocked. An attacker can exploit this by crafting commands using GNU env -S wrapper semantics that policy checking treats as safe but runtime executes as dangerous.
Technical details
The vulnerability is an interpretation conflict (CWE-436) in the exec allowlist/safeBins policy evaluation. The root cause is a mismatch between how policy analysis resolves wrapper commands and how runtime execution actually interprets them: analysis unwraps argv semantics to validate a command, but execution can still run the original wrapper semantics, allowing bypass. Additionally, safe-bin short-flag handling accepts unknown short options in flag clusters. An attacker able to inject command text into an exec-capable flow can craft commands using GNU env -S/--split-string that pass policy checks but execute different payloads at runtime. The fix enforces analysis/runtime parity by introducing wrapper execution planning with semantic-wrapper blocking, carrying planned effectiveArgv through resolution, evaluating allowlist against planned argv, and rejecting unknown short safe-bin flags. Patched in version 2026.2.23.
Affected products
- OpenClaw OpenClaw through 2026.2.22-2
Timeline
- 2026-03-03: disclosed: GHSA-796m-2973-wc5q published
- 2026-02-24: patched: Fix commit a1c4bf07c6baad3ef87a0e710fe9aef127b1f606
- 2026-02-23: patched: Version 2026.2.23 released with patch