Junglewise Threat Intelligence

OpenClaw system.run approval identity mismatch

Severity: low · CVSS 3.1 · Published 2026-03-21

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a workflow automation platform that allows administrators to approve and execute commands. This vulnerability allows an attacker to execute a different command than what an administrator approved by exploiting a whitespace-handling mismatch between the approval display and runtime execution. An attacker who can influence command arguments and reuse an approval could run arbitrary code with the privileges of the OpenClaw service.

Technical details

This is an approval-integrity bypass vulnerability in OpenClaw's system.run command approval workflow. The vulnerability stems from an identity mismatch: when approving commands, the system displays a normalized version of the command (with trimmed argv token whitespace), but at runtime, it executes using the raw, untrimmed argv. An attacker can craft a trailing-space executable token in the command arguments that will appear as a benign command to the approver but execute a different binary at runtime. Exploitation requires that an attacker can influence command argv and reuse/obtain a matching approval context. The fix was released in version 2026.2.25.

Affected products

  • OpenClaw OpenClaw ≤2026.2.24

Timeline

  • 2026-02-26: disclosed
  • 2026-02-26: patched: Version 2026.2.25 released with fix

References

Related threats