Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p4wh-cr8m-gm6c

Опубликовано: 03 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.8
CVSS3: 6.1

Описание

OpenClaw: shell-env trusted-prefix fallback allowed attacker-controlled binary execution via $SHELL

Summary

shell-env fallback trusted prefix-based executable paths for $SHELL, allowing execution of attacker-controlled binaries in local/runtime-env influence scenarios.

Details

In affected versions, shell selection accepted either:

  1. a shell listed in /etc/shells, or
  2. any executable under hardcoded trusted prefixes (/bin, /usr/bin, /usr/local/bin, /opt/homebrew/bin, /run/current-system/sw/bin).

The selected shell was then executed as a login shell (-l -c 'env -0') for PATH/environment probing.

On systems where a trusted-prefix directory is writable (for example common Homebrew layouts under /opt/homebrew/bin) and runtime $SHELL can be influenced, this enabled attacker-controlled binary execution in OpenClaw process context.

The fix removes the trusted-prefix executable fallback and now trusts only shells explicitly registered in /etc/shells; otherwise it falls back to /bin/sh.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected versions: >= 2026.2.22, <= 2026.2.22-2
  • Latest published vulnerable version: 2026.2.22-2
  • Patched versions (released): >= 2026.2.23

Fix Commit(s)

  • ff10fe8b91670044a6bb0cd85deb736a0ec8fb55

Release Process Note

This advisory sets patched_versions to the released version (2026.2.23). This advisory now reflects released fix version 2026.2.23.

OpenClaw thanks @tdjackey for reporting.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

>= 2026.2.22, < 2026.2.23

2026.2.23

EPSS

Процентиль: 3%
0.00125
Низкий

5.8 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-184
CWE-829

Связанные уязвимости

CVSS3: 6.1
nvd
5 месяцев назад

OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allows attackers to execute attacker-controlled binaries by exploiting trusted-prefix fallback logic for the $SHELL variable. An attacker can influence the $SHELL environment variable on systems with writable trusted-prefix directories such as /opt/homebrew/bin to execute arbitrary binaries in the OpenClaw process context.

CVSS3: 6.1
fstec
6 месяцев назад

Уязвимость пакета shell-env ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 3%
0.00125
Низкий

5.8 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-184
CWE-829