Arbitrary Command Execution Vulnerability in OpenClaw Windows Node
Article Content
- •Vulnerability allows arbitrary command execution via exec-approval policy flaws.
- •Affected commands can bypass security checks using pipes and command substitutions.
- •No patches have been released, leaving systems vulnerable.
A critical vulnerability in the OpenClaw Windows node's exec-approval policy allows arbitrary command execution. The flaw arises from improper handling of command chains, specifically with pipe operators (|) and command substitutions ($(...)). This oversight means that a command like 'echo ok | del ...' can execute the denied command without triggering security checks. Both articles highlight that the vulnerability could allow a connected agent to bypass the allowlist and execute unauthorized commands on the host. The issue has been classified under CWE-863 (Incorrect Authorization) and CWE-78 (OS Command Injection). The vulnerability affects all versions of the OpenClaw Windows node that utilize the flawed exec-approval mechanism. As of now, no patches have been reported to address this issue, and it remains a significant security concern.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What systems are affected?
Is there a patch available?
What should organizations do?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…