OS Command Injection in OpenClaw - #VU135907
Published: June 30, 2026
Vulnerability details
The vulnerability allows a remote user to execute or persist unauthorized actions.
The vulnerability exists due to improper neutralization of special elements used in an os command in the device-pair approval feature exposing node system.run when handling lower-trust caller input or configured input paths. A remote user can supply crafted input to execute or persist unauthorized actions.
Only instances where the affected feature is enabled and reachable are vulnerable.