CVE-2026-22168

OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows authenticated operators to execute arbitrary trailing arguments after cmd.exe /c while approval text reflects only a benign command. Attackers can smuggle malicious arguments through cmd.exe /c to achieve local command execution on trusted Windows nodes with mismatched audit logs.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

19 Mar 2026, 14:48

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/6007941f04df1edcca679dd6c95949744fdbd4df - () https://github.com/openclaw/openclaw/commit/6007941f04df1edcca679dd6c95949744fdbd4df - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-5v6x-rfc3-7qfr - () https://github.com/openclaw/openclaw/security/advisories/GHSA-5v6x-rfc3-7qfr - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-command-injection-via-cmd-exe-c-trailing-arguments-in-system-run - () https://www.vulncheck.com/advisories/openclaw-command-injection-via-cmd-exe-c-trailing-arguments-in-system-run - Third Party Advisory
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) Versiones de OpenClaw anteriores a 2026.2.21 contienen una vulnerabilidad de discrepancia de integridad de aprobación en system.run que permite a operadores autenticados ejecutar argumentos finales arbitrarios después de cmd.exe /c mientras que el texto de aprobación refleja solo un comando benigno. Los atacantes pueden introducir argumentos maliciosos a través de cmd.exe /c para lograr la ejecución de comandos local en nodos Windows de confianza con registros de auditoría no coincidentes.

18 Mar 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-18 02:16

Updated : 2026-03-19 14:48


NVD link : CVE-2026-22168

Mitre link : CVE-2026-22168

CVE.ORG link : CVE-2026-22168


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')