Inclusion of Functionality from Untrusted Control Sphere in OpenClaw - CVE-2026-22217

 

Inclusion of Functionality from Untrusted Control Sphere in OpenClaw - CVE-2026-22217

Published: May 1, 2026


Vulnerability identifier: #VU128796
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-22217
CWE-ID: CWE-829
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: OpenClaw
Affected software:
OpenClaw

Detailed vulnerability description

The vulnerability allows a local user to execute attacker-controlled binaries.

The vulnerability exists due to inclusion of functionality from an untrusted control sphere in shell-env shell selection when processing an attacker-influenced $SHELL value and accepting executable paths under trusted prefixes. A local user can place or reference a crafted executable via $SHELL to execute attacker-controlled binaries.

Exploitation requires a writable trusted-prefix directory and influence over the runtime $SHELL environment variable.


How to mitigate CVE-2026-22217

Install security update from vendor's website.

Sources