Discovered: 2026-02-04 Reporter: @akhmittra
OpenClaw previously accepted untrusted PATH sources in limited situations. In affected versions, this could cause OpenClaw to resolve and execute an unintended binary ("command hijacking") when running host commands.
This issue primarily matters when OpenClaw is relying on allowlist/safe-bin protections and expects PATH to be trustworthy.
openclaw (npm)< 2026.2.14>= 2026.2.14 (planned next release)An attacker needs all of the following:
system.run).system.run.PATH) into system.run.PATH (for example, a writable directory on the node host), with a name that matches an allowlisted/safe-bin command that OpenClaw will run.Notes:
An attacker needs all of the following:
node_modules/.bin/openclaw and additional attacker-controlled executables in the same directory.PATH) that matches one of those attacker-controlled executables.node_modules/.bin PATH bootstrapping is now disabled by default. If explicitly enabled, it is append-only (never prepended) via OPENCLAW_ALLOW_PROJECT_LOCAL_BIN=1.PATH overrides.Thanks @akhmittra for reporting.
{
"cwe_ids": [
"CWE-427",
"CWE-78",
"CWE-807"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-18T00:55:50Z",
"nvd_published_at": "2026-03-05T22:16:24Z",
"severity": "HIGH"
}