CVE-2026-31997

OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run approvals, allowing post-approval executable rebind attacks. Attackers can modify PATH resolution after approval to execute a different binary than the operator approved, enabling arbitrary command execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:34

Type Values Removed Values Added
Summary
  • (es) Versiones de OpenClaw anteriores a 2026.3.1 no logran fijar la identidad del ejecutable para tokens argv[0] que no tienen formato de ruta en las aprobaciones de system.run, permitiendo ataques de reasignación de ejecutable posteriores a la aprobación. Los atacantes pueden modificar la resolución de PATH después de la aprobación para ejecutar un binario diferente al que aprobó el operador, posibilitando la ejecución arbitraria de comandos.

19 Mar 2026, 18:49

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-q399-23r3-hfx4 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-q399-23r3-hfx4 - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-executable-rebind-via-unbound-path-token-in-system-run-approvals - () https://www.vulncheck.com/advisories/openclaw-executable-rebind-via-unbound-path-token-in-system-run-approvals - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

19 Mar 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 02:16

Updated : 2026-06-17 10:34


NVD link : CVE-2026-31997

Mitre link : CVE-2026-31997

CVE.ORG link : CVE-2026-31997


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition