CVE-2026-22217Disclosure(openclaw / openclaw)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allows attackers to execute attacker-controlled binaries by exploiting trusted-prefix fallback logic for the $SHELL variable. An attacker can influence the $SHELL environment variable on systems with writable trusted-prefix directories such as /opt/homebrew/bin to execute arbitrary binaries in the OpenClaw process context.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-18); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-18: 3Mentions · 2026-03-19: 1Technical Details · 2026-03-18: 203-1803-19
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-183
Disclosure2General1
2026-03-191
General1
Full discourse4 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-22217 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-22217-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-22217 #openclaw #

    Post summary

    The tweet simply announces a CVE alert for CVE-2026-22217 related to OpenClaw and links to an external article, but it does not provide technical details, PoC information, or evidence of exploitation or patch status.

    0000076
    3.6K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-22217 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-22217 #CVE-2026-22217 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/qGllS6afb0

    Post summary

    The tweet announces a new CVE‑2026‑22217 with a 5.3 severity rating and a medium risk level, affecting unspecified products, and provides only a reference to the NVD entry without technical details, exploit code, or patch information.

    0000024
    104 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22217 OpenClaw version 2026.2.22 prior to 2026.2.23 contain an arbitrary code execution vulnerability in shell-env that allows attackers to execute attacker-controlled bina… https://www.cve.org/CVERecord?id=CVE-2026-22217

    Post summary

    CVE‑2026‑22217 is a newly disclosed arbitrary‑code‑execution flaw in OpenClaw's shell‑env module; no PoC, exploit tool, or active exploitation data is reported.

    0000092
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22217 OpenClaw Shell Environment Arbitrary Code Execution via $SHELL Variable Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22217

    Post summary

    The text announces CVE-2026-22217 as an Arbitrary Code Execution vulnerability in OpenClaw by manipulating the $SHELL variable, with no evidence of PoC, exploit, patch, or active exploitation.

    0000068
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more