OS Command Injection in OpenClaw - CVE-2026-31995
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary commands.
The vulnerability exists due to command injection in the Windows Lobster shell fallback path when retrying certain spawn failures with shell execution enabled. A local user can supply crafted tool-provided arguments to execute arbitrary commands.
Exploitation requires Windows, fallback-triggering conditions for ENOENT or EINVAL spawn failures, and control over arguments through a local operator-defined workflow.