OS Command Injection in OpenClaw - #VU129437
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary commands.
The vulnerability exists due to improper neutralization of special elements used in an os command in the Gateway /tools/invoke endpoint when invoking high-risk session orchestration tools over HTTP. A remote user can invoke tools such as sessions_spawn or sessions_send to execute arbitrary commands.
This issue requires a valid Gateway token and may also enable cross-session message injection.