This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: OpenClaw suffers from **Parameter Injection** via command substitution. ๐ **Consequences**: Attackers bypass the approved allowlist to execute **arbitrary commands** on the system.โฆ
๐ก๏ธ **Root Cause**: **CWE-78** (OS Command Injection). The flaw lies in how the system handles **command substitution within double quotes**, allowing malicious syntax to slip past the allowlist checks. ๐
Q3Who is affected? (Versions/Components)
๐ฅ **Affected**: Users of **OpenClaw** (the open-source AI assistant). ๐ **Versions**: All versions **prior to 2026.2.2**. If you are running an older build, you are vulnerable. โ ๏ธ
Q4What can hackers do? (Privileges/Data)
๐ป **Capabilities**: Hackers gain **Remote Code Execution (RCE)**. ๐๏ธ They can achieve **High Confidentiality, Integrity, and Availability** loss. Essentially, full system control is possible without authentication. ๐
Q5Is exploitation threshold high? (Auth/Config)
๐ **Threshold**: **LOW**. ๐ซ **Auth**: None required (PR:N). ๐ **Network**: Remote (AV:N). ๐ฑ๏ธ **User Interaction**: None needed (UI:N). This is a high-severity, easy-to-exploit vulnerability. ๐ฏ
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ **Exploit Status**: No specific PoC code is listed in the data (POCs: []). However, the vulnerability mechanism (command substitution bypass) is well-documented in the advisory.โฆ
๐ **Self-Check**: Verify your OpenClaw version. ๐ Look for usage of **command substitution inside double quotes** in your configuration or inputs.โฆ
โ **Fix Status**: **YES**. The vendor has released a patch. ๐ฆ **Target Version**: Upgrade to **OpenClaw 2026.2.2** or later. ๐ See the GitHub Security Advisory (GHSA-3hcm-ggvf-rch5) for details. ๐
Q9What if no patch? (Workaround)
๐ง **No Patch?**: If you cannot upgrade immediately, strictly **sanitize inputs** to prevent command substitution characters. ๐ซ Disable any features allowing direct command execution via user input.โฆ
๐ฅ **Urgency**: **CRITICAL**. ๐จ With a CVSS score of 9.8 and no auth required, this is a top-priority fix. ๐โโ๏ธ Patch immediately to prevent remote code execution. โณ Time is of the essence! โฐ