Executive brief
OpenClaw is a JavaScript library that provides secure command execution with an allowlist security feature to control which commands can be run. An attacker can bypass this allowlist protection by using shell line-continuation characters to split command substitution syntax across lines, tricking the analyzer into approving malicious commands that execute unintended subcommands at runtime.
Technical details
This is an authorization bypass vulnerability (CWE-78, CWE-863) in OpenClaw's system.run allowlist validation mechanism. The vulnerability exists when tools.exec.security is set to allowlist mode. An attacker can inject $\ followed by a newline and opening parenthesis inside double quotes, causing the shell parser to fold the line continuation into executable command substitution $(...) syntax that circumvents the static analysis used during approval. The vulnerability requires local network access and authenticated/privileged usage context (PR:L in CVSS), but allows execution of non-allowlisted commands. The issue was fixed in version 2026.2.22.
Affected products
- OpenClaw OpenClaw before 2026.2.22
Timeline
- 2026-02-23: disclosed
- 2026-02-23: patched: Fix committed; patched version 2026.2.22 planned