Описание
OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generation where environment variables are written to gateway.cmd using unquoted set KEY=VALUE assignments, allowing shell metacharacters to break out of assignment context. Attackers can inject arbitrary commands through environment variable values containing metacharacters like &, |, ^, %, or ! to achieve command execution when the scheduled task script is generated and executed.
Ссылки
- Patch
- MitigationVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
EPSS
6.1 Medium
CVSS3
7.8 High
CVSS3
Дефекты
Связанные уязвимости
OpenClaw has a Command Injection via unescaped environment assignments in Windows Scheduled Task script generation
Уязвимость сценария src/daemon/schtasks.ts ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю выполнить произвольные команды
EPSS
6.1 Medium
CVSS3
7.8 High
CVSS3