PT-2026-26233 · Openclaw · Openclaw

·

CVE-2026-31993

·

Publicado

2026-02-21

·

Atualizado

2026-03-20

CVSS v2.0

6.8

Média

VetorAV:N/AC:H/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.22
Description The OpenClaw macOS companion app contains a flaw in how it parses allowlists, potentially allowing authenticated operators to bypass execution approval checks. Specifically, attackers with operator.write privileges and a paired macOS beta node can create shell-chain payloads that circumvent incomplete allowlist validation, leading to arbitrary command execution on the paired host. This requires exec approvals to be set to security=allowlist and ask=on-miss. The issue stems from unsafe shell-substitution parsing in allowlist mode. The fix involves hardening macOS allowlist resolution by evaluating shell chains per segment and failing closed on unsafe parsing.
Recommendations OpenClaw versions prior to 2026.2.22 should be updated.

Exploit

Correção

Improper Authorization

Incomplete List of Disallowed Inputs

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05009
CVE-2026-31993
GHSA-5326-6F73-M96W
GHSA-5F9P-F3W2-FWCH

Produtos afetados

Openclaw