OpenClaw Windows Scheduled Task script generation allowed unsafe argument handling in generated gateway.cmd files. In vulnerable versions, cmd metacharacter-only values could be emitted without safe quoting/escaping, which could lead to unintended command execution when the scheduled task runs.
The issue affected Windows daemon startup script generation in src/daemon/schtasks.ts.
Vulnerable behavior included:
The fix hardens Windows script generation by:
% / ! expansion cases.This issue is local to Windows deployments and requires control over values that feed service script generation (for example install-time/runtime arguments or environment-derived values). It can result in unintended command execution in the scheduled task context.
openclaw (npm)<= 2026.2.17>= 2026.2.19 (planned next npm release)2026.2.17280c6b117b2f0e24f398e5219048cd4cc3b82396OpenClaw thanks @tdjackey for reporting.
{
"cwe_ids": [
"CWE-116"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-03T21:37:29Z",
"nvd_published_at": null,
"severity": "HIGH"
}