Junglewise Threat Intelligence

OpenClaw shell expansion bypass in unquoted heredocs

Severity: medium · CVSS 5.3 · Published 2026-05-04

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a library used for executing system commands. A vulnerability in its command filtering system allows specially crafted commands to bypass security checks by hiding malicious instructions inside unquoted 'heredoc' blocks. This could allow an attacker to execute unauthorized shell commands that appear safe to the system's security filters.

Technical details

The OpenClaw npm package's exec allowlist analyzer fails to account for shell expansion within unquoted heredoc bodies. An attacker can provide a command that includes an unquoted heredoc containing shell expansion tokens or continuation-splice bypasses, which the analyzer treats as literal text but the shell evaluates at runtime. This allows for the execution of arbitrary shell logic within what is otherwise an approved command. The fix, introduced in version 2026.4.22, updates the analyzer to track heredoc bodies and reject unquoted expansion tokens.

Affected products

  • openclaw openclaw <= 2026.4.21

Timeline

  • 2026-04-23: disclosed: Advisory published on GitHub
  • 2026-04-23: patched: Fix commit b2e8b7d released
  • 2026-05-04: advisory: GitHub Advisory reviewed and published to database

References

Related threats