OS Command Injection in OpenClaw - #VU132699
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to execute shell-provided content outside the intended allowlist rule.
The vulnerability exists due to command injection in the strict inline-eval checks for shell carrier handling when processing a command request that combines allowlisted tools with shell positional arguments. A remote user can send a specially crafted command request to execute shell-provided content outside the intended allowlist rule.
Only configurations where the affected feature is enabled and reachable are vulnerable.