Incomplete List of Disallowed Inputs in OpenClaw - CVE-2026-31992
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to execute unintended commands.
The vulnerability exists due to an incomplete list of disallowed inputs in the system.run allowlist guard when processing env -S shell wrapper payloads. A remote user can supply crafted tool input to execute unintended commands.
This issue causes a mismatch between policy analysis and runtime execution in allowlist mode.