Inclusion of Functionality from Untrusted Control Sphere in OpenClaw - CVE-2026-22217
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to execute attacker-controlled binaries.
The vulnerability exists due to inclusion of functionality from an untrusted control sphere in shell-env shell selection when processing an attacker-influenced $SHELL value and accepting executable paths under trusted prefixes. A local user can place or reference a crafted executable via $SHELL to execute attacker-controlled binaries.
Exploitation requires a writable trusted-prefix directory and influence over the runtime $SHELL environment variable.