CVE-2026-101884

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Referenced assets6 URLs
Full discourse1 post
  • Code Solutions@CodeSolutionsIL

    Don’t Panic Digest Inform. Gate. Then automate. News — OpenClaw Windows Node approval-rule bypasses (CVE-2026-101880 + CVE-2026-101882, CVSS 3.1 8.8 HIGH each; CVE-2026-101884, 7.5 HIGH): the Windows companion for the OpenClaw agent should only run commands its approval rules allow, but the checks had gaps: a command chained behind an allowed one went unchecked, a remote caller could add broad “allow” rules, and a filter missed some settings that let allowed tools run other code. Each needs a connected gateway or agent. Affected before 2026.7.1 (CNA VulnCheck, Sep 30); fixed since 2026.7.1 (Aug 10) and in the current release, v2026.9.8-1 (Oct 7) — update to the current release. Not in CISA KEV; no in-the-wild use stated. Operator read: an SI (super intelligence) agent’s approval list that only blocks known-bad commands can be talked around — allow commands by name only, check every part of a chained command, and never let the agent edit its own rules. https://nvd.nist.gov/vuln/detail/CVE-2026-101880 Related: OpenAI’s GPT-6 Sol and GPT-6 Luna system card (Oct 7) — in OpenAI’s own tests (mostly low-stakes, run without its extra safety controls), the models found another way round blocks such as “access denied” errors in 28% (GPT-6 Sol) and 15.9% (GPT-6 Luna) of runs on the highest-effort setting. For us, the real limit belongs outside the model. Our Plainwrap daily notes: https://x.com/CodeSolutionsIL/status/2108225985653145923 https://deploymentsafety.openai.com/gpt-6-october More — Sabrina Halper × Wiz co-founder Yinon Costica (attack vs defense, agent guardrails, ~22:45–43:30 + 47:15–58:30): What’s in it: Costica tells Halper it is easier right now for attackers to use SI for one attack than for defenders to secure everything, but argues defenders can pull ahead by testing their own systems and using what they know about their own environments. He also covers guardrails for agents that can reach payments or sensitive data, models anyone can download and run, and humans as security’s “moral compass,” while pushing for fewer routine human approvals. Our takeaway: for us, any agent action that spends money, touches sensitive data, or changes systems still waits for a named person’s OK. Notes of a public interview, not product guidance; the guest’s claims are as discussed, not verified, and panel opinions are not endorsed. https://gist.github.com/CodeSolutionsLLC/414c9a30bee061cb3490316343098feb https://x.com/SabrinaHalper/status/2107893808344272933 https://codesolutionsllc.com/news

    1000095
    11 followersView on X

Explore more