OS Command Injection in OpenClaw - CVE-2026-28460
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to execute unintended commands.
The vulnerability exists due to command injection in the system.run shell-wrapper analysis in allowlist mode when processing shell commands containing line-continuation command substitution inside double quotes. A remote attacker can supply a specially crafted command string to execute unintended commands.
Only deployments that enable tools.exec.security=allowlist with ask=on-miss or off are vulnerable.