OS Command Injection in OpenClaw - CVE-2026-25593
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to command injection in the Gateway WebSocket API config.apply functionality when processing crafted cliPath values for command discovery. A remote attacker can send a specially crafted WebSocket request to execute arbitrary commands.
The injected commands run as the gateway process user.