CVE-2026-22175

OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always grants could be circumvented through unrecognized multiplexer shell wrappers like busybox and toybox sh -c commands. Attackers can exploit this by invoking arbitrary payloads under the same multiplexer wrapper to satisfy stored allowlist rules, bypassing intended execution restrictions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

19 Mar 2026, 16:06

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/commit/a67689a7e3ad494b6637c76235a664322d526f9e - () https://github.com/openclaw/openclaw/commit/a67689a7e3ad494b6637c76235a664322d526f9e - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-gwqp-86q6-w47g - () https://github.com/openclaw/openclaw/security/advisories/GHSA-gwqp-86q6-w47g - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-exec-approval-bypass-via-unrecognized-multiplexer-shell-wrappers - () https://www.vulncheck.com/advisories/openclaw-exec-approval-bypass-via-unrecognized-multiplexer-shell-wrappers - Third Party Advisory

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) Versiones de OpenClaw anteriores a 2026.2.23 contienen una vulnerabilidad de omisión de aprobación de ejecución en modo de lista de permitidos donde las concesiones de 'permitir siempre' podrían ser eludidas a través de envoltorios de shell de multiplexor no reconocidos como los comandos 'sh -c' de busybox y toybox. Los atacantes pueden explotar esto invocando cargas útiles arbitrarias bajo el mismo envoltorio de multiplexor para satisfacer las reglas de lista de permitidos almacenadas, omitiendo las restricciones de ejecución previstas.

18 Mar 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-18 02:16

Updated : 2026-03-19 16:06


NVD link : CVE-2026-22175

Mitre link : CVE-2026-22175

CVE.ORG link : CVE-2026-22175


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-184

Incomplete List of Disallowed Inputs