Описание
OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script generation due to unsafe handling of cmd metacharacters and expansion-sensitive characters in gateway.cmd files. Local attackers with control over service script generation arguments can inject arbitrary commands by providing metacharacter-only values or CR/LF sequences that execute unintended code in the scheduled task context.
Ссылки
- Patch
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Одновременно
EPSS
7.1 High
CVSS3
7.8 High
CVSS3
Дефекты
Связанные уязвимости
OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling
Уязвимость сценария src/daemon/schtasks.ts ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю выполнить произвольные команды
EPSS
7.1 High
CVSS3
7.8 High
CVSS3