PT-2026-99220 · Openclaw · Openclaw
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.2.26 through 2026.7.0
Description
On Windows hosts running in exec allowlist mode, PowerShell command analysis may approve an executable resolved from PATH but execute a different file with the same name located in the workspace directory. This occurs when a command uses a bare executable name, allowing lower-trust content to place a malicious executable with an approved basename into an agent-writable workspace. Consequently, the agent may execute the workspace file instead of the intended allowlisted path, leading to arbitrary code execution with the privileges of the Gateway or node-host user.
Recommendations
Update to version 2026.7.1.
Avoid using bare executable names in approved PowerShell commands.
Keep executable files out of agent-writable workspaces.
Exploit
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw