Junglewise Threat Intelligence

OpenClaw macOS companion app allowlist parsing mismatch in system.run

Severity: low · CVSS 3.1 · Published 2026-03-19

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a macOS companion application that manages execution approvals and command authorization on paired hosts. A parsing flaw in the allowlist validation mechanism allows authenticated operators with elevated privileges to craft shell-chain commands that bypass approval checks and execute arbitrary commands on paired macOS systems, potentially compromising system integrity and data access.

Technical details

The vulnerability is a CWE-184 (Incomplete List of Disallowed Inputs) / CWE-285 (Improper Authorization) in the macOS companion app's exec approval evaluation. The allowlist parser fails to properly detect shell control and expansion syntax (&&, ||, ;, |, backticks, $, <, >, parentheses) in raw shell text, allowing first-token resolution to approve shell-chain payloads that should be rejected. This requires the attacker to be an authenticated caller with operator.write privileges, a paired macOS beta node, and the host configured with security=allowlist and ask=on-miss settings. An attacker meeting these preconditions can bypass approval workflows and execute arbitrary shell commands. The vulnerability was fixed in version 2026.2.22 by hardening the allowlist resolution to evaluate shell chains per segment and fail closed on unsafe shell-substitution parsing in allowlist mode.

Affected products

  • OpenClaw openclaw < 2026.2.22

Timeline

  • 2026-02-23: disclosed
  • 2026-02-22: patched: Version 2026.2.22 released with hardened allowlist checks
  • 2026-03-19: advisory: GHSA-5f9p-f3w2-fwch published; GHSA-5326-6f73-m96w marked as duplicate and withdrawn

References