#VU125107 Time-of-check Time-of-use (TOCTOU) Race Condition in OpenClaw - CVE-2026-31997
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to execute a different executable than the operator approved.
The vulnerability exists due to a time-of-check time-of-use race condition in node system.run approvals when resolving non-path-like argv[0] PATH tokens for host=node runs. A remote user can change PATH resolution after approval to execute a different executable than the operator approved.
The issue affects previously approved actions that use non-path-like command tokens such as tr.