Incomplete List of Disallowed Inputs in OpenClaw - CVE-2026-31993
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to execute shell-chain commands on the paired macOS host.
The vulnerability exists due to incomplete list-based input validation in system.run exec approvals when processing shell-chain commands under allowlist mode with ask-on-miss enabled. A remote user can submit a shell-chain command that passes allowlist checks to execute shell-chain commands on the paired macOS host.
Exploitation requires operator.write permissions on a paired macOS beta node host, and only systems configured with security=allowlist and ask=on-miss are affected.