Untrusted search path in OpenClaw - #VU132746
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to execute an unintended local executable.
The vulnerability exists due to improper control of search path in trash command selection when maintenance tasks use a workspace-derived service PATH. A remote user can influence the service PATH to cause execution of a local executable the operator did not intend to run.
Exploitation requires the affected feature to be enabled and reachable.