Skip to content
Critical LLM Command Injection Vulnerability Discovered in OpenClaw Framework

Critical LLM Command Injection Vulnerability Discovered in OpenClaw Framework

First seen 16 Mar 2026, 17:52 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 17, 2026 at 17:42 UTC
  • •A critical LLM-driven command injection vulnerability was discovered in OpenClaw.
  • •Attackers can achieve remote code execution and steal sensitive data due to improper command argument escaping.
  • •Remediation recommendations have been submitted to relevant security databases and communities.

A joint team from the China Academy of Information and Communications Technology, Shanghai Jiao Tong University, and Nanjing University has identified a critical LLM-driven command injection vulnerability in the bash-tools module of the open-source autonomous agent framework OpenClaw during a security audit. This vulnerability is due to improper escaping of command-line arguments generated by the LLM, enabling attackers to bypass regex defenses through crafted prompts, leading to remote code execution and potential data theft. The vulnerability has been validated across multiple mainstream model environments. The research team has initiated a responsible disclosure process and submitted remediation recommendations to the NVDB Artificial Intelligence Product Security Vulnerability Database (CAIVD) and the GitHub community. The situation is currently being monitored as the vulnerability poses significant risks to systems utilizing OpenClaw.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 207d ago How this analysis works

Timeline

2026-03-16
Discovery of LLM command injection vulnerability in OpenClaw
2026-03-16
Responsible vulnerability disclosure process initiated
2026-03-16
Remediation recommendations submitted to CAIVD and GitHub

More articles in this cluster (4)