Skip to content
Arbitrary Command Execution Vulnerability in OpenClaw Windows Node

Arbitrary Command Execution Vulnerability in OpenClaw Windows Node

First seen 1 Oct 2026, 01:58 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 01:59 UTC
  • •Vulnerability allows arbitrary command execution via exec-approval policy flaws.
  • •Affected commands can bypass security checks using pipes and command substitutions.
  • •No patches have been released, leaving systems vulnerable.

A critical vulnerability in the OpenClaw Windows node's exec-approval policy allows arbitrary command execution. The flaw arises from improper handling of command chains, specifically with pipe operators (|) and command substitutions ($(...)). This oversight means that a command like 'echo ok | del ...' can execute the denied command without triggering security checks. Both articles highlight that the vulnerability could allow a connected agent to bypass the allowlist and execute unauthorized commands on the host. The issue has been classified under CWE-863 (Incorrect Authorization) and CWE-78 (OS Command Injection). The vulnerability affects all versions of the OpenClaw Windows node that utilize the flawed exec-approval mechanism. As of now, no patches have been reported to address this issue, and it remains a significant security concern.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
Vulnerability disclosed
OpenClaw published advisories detailing the exec-approval policy flaw allowing arbitrary command execution.
github.com
2026-10-01
Second advisory published
A follow-up advisory confirmed the same vulnerability and detailed the exploit vector involving pipes and substitutions.
github.com

More articles in this cluster (2)

Common questions

What systems are affected?
All versions of the OpenClaw Windows node that utilize the exec-approval policy are affected.
Is there a patch available?
No patches have been released to address this vulnerability as of now.
What should organizations do?
Organizations should monitor for updates from OpenClaw and consider restricting the use of the exec-approval feature until a fix is available.