Junglewise Threat Intelligence

OpenClaw untrusted search path in maintenance task execution

Severity: low · CVSS 3.1 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI automation platform that executes tasks across operating systems and platforms. A vulnerability in versions before 2026.5.2 allows authenticated operators to indirectly influence which system executables are invoked during maintenance operations by manipulating workspace-derived environment paths. An attacker with operator-level access could potentially execute arbitrary commands on the system by crafting malicious workspace paths.

Technical details

The vulnerability is classified as CWE-426 (Untrusted Search Path) and affects OpenClaw's maintenance task execution feature. The root cause is that the application derives executable search paths from workspace configuration, allowing an authenticated operator to influence which trash/cleanup executable is selected and executed during maintenance operations. The attack requires local system access and authenticated operator privileges but does not require user interaction. An attacker can exploit this to execute arbitrary local executables from unintended paths by manipulating workspace-derived environment variables. The vulnerability has been patched in version 2026.5.2. Mitigations prior to patching include restricting maintenance flows to trusted workspaces with fixed service paths and disabling the affected feature when not required.

Affected products

  • OpenClaw openclaw < 2026.5.2

Timeline

  • 2026-05-28: disclosed: Original advisory GHSA-rx78-29qr-5hq8 published
  • 2026-06-16: advisory: Duplicate advisory GHSA-2w22-3f6x-3hf4 published
  • 2026-06-18: other: GHSA-2w22-3f6x-3hf4 withdrawn as duplicate
  • 2026-05-28: patched: Patched version 2026.5.2 released

References