Junglewise Threat Intelligence

OpenClaw OS command injection via shell expansion in system.run

Severity: high · CVSS 7.1 · Published 2026-07-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a platform for managing distributed nodes, contains a security flaw in how it validates commands on POSIX-based systems. An authenticated user with low privileges could bypass security allowlists by using special shell characters to manipulate command arguments. This could allow an attacker to read sensitive configuration files or other private data stored on the affected node.

Technical details

A vulnerability exists in OpenClaw's `system.run` command execution on POSIX nodes due to improper neutralization of special elements (CWE-78). The security mechanism validates commands against a 'safe-bin' allowlist before shell expansion occurs. An attacker can provide input that appears as a single safe argument but expands into multiple shell words, effectively injecting additional file operands or arguments. This allows an authenticated operator to bypass intended policy restrictions and read node-local files, including configuration data. The issue is addressed in version 2026.5.18.

Affected products

  • OpenClaw openclaw < 2026.5.18

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: patched: First stable patched version 2026.5.18 released
  • 2026-07-02: advisory

References

Related threats