Interpretation Conflict in OpenClaw - #VU128786
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to execute unexpected commands.
The vulnerability exists due to interpretation conflict in tools.exec allowlist/safe-bins evaluation when processing wrapper commands using GNU env -S/--split-string semantics. A remote attacker can influence tool command text to execute unexpected commands.
Exploitation requires the ability to influence tool command text reaching an exec-capable flow, such as through untrusted prompt or content injection.