Improper Neutralization of Argument Delimiters in a Command in OpenClaw - CVE-2026-29608

 

Improper Neutralization of Argument Delimiters in a Command in OpenClaw - CVE-2026-29608

Published: April 8, 2026


Vulnerability identifier: #VU125121
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-29608
CWE-ID: CWE-88
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute unintended local scripts.

The vulnerability exists due to improper neutralization of argument delimiters in system.run approval hardening in the node host when rewriting wrapper command argv. A local user can influence wrapper argv and place a local file in the approved working directory to execute unintended local scripts.

User interaction is required because the operator must approve the displayed command.


Affected software

OpenClaw

How to mitigate CVE-2026-29608

Install security update from vendor's website.

OpenClaw - update to 2026.3.2

External References

Related Security Bulletins