CVE-2026-24763Disclosure(openclaw / openclaw)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed in OpenClaw’s Docker sandbox execution mechanism due to unsafe handling of the PATH environment variable when constructing shell commands. An authenticated user able to control environment variables could influence command execution within the container context. This vulnerability is fixed in 2026.1.29.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 3 mentions (2026-02-03); latest day: 1
  • 10 total mentions across 8 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline10 mentions / 8d
01223Mentions · 2026-02-02: 1Mentions · 2026-02-03: 3Mentions · 2026-02-04: 1Mentions · 2026-02-12: 1Mentions · 2026-02-14: 1Mentions · 2026-02-19: 1Mentions · 2026-03-18: 1Mentions · 2026-06-06: 1Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-06-06: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 3Technical Details · 2026-02-04: 1Technical Details · 2026-02-19: 1Technical Details · 2026-03-18: 1Technical Details · 2026-06-06: 102-0202-0302-0402-1202-1402-1903-1806-06
Signal classification3 categories
Disclosure
550.0%
Patch
330.0%
General
220.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-021
Patch1
2026-02-033
Disclosure2Patch1
2026-02-041
Disclosure1
2026-02-121
General1
2026-02-141
General1
2026-02-191
Disclosure1
2026-03-181
Disclosure1
2026-06-061
Patch1
Full discourse10 posts
  • Coyote Security Scanner@CoyoteSecure
    General

    Just pushed v1.5 of Coyote, this was a big update, see details below: - Added scans for all five OpenClaw CVEs in openclaw .py: CVE-2026-25253 CVE-2026-24763 CVE-2026-25157 CVE-2026-25475 CVE-2026-25593 These include version-threshold detection plus config-risk indicators, and are now part of secure-openclaw output. - Updated version handling in OpenClaw report output in output .py so “outdated” uses the latest tracked OpenClaw fix level (2026.1.30). - Bumped Coyote version to 1.4.0 in:__init__.py README .md (displayed version text) - Updated OpenClaw command/help text in:__main__.py - Updated README OpenClaw section in:README .md to document all five CVEs, updated checks table, and refreshed example output. - Created the new doc: OpenClawCVEs .md with all OpenClaw CVEs Coyote scans for, fixed versions, and scan logic. - Added tests in: test_openclaw_security.py

    Post summary

    The message announces a new Coyote tool release that adds scanning for five OpenClaw CVEs, with no exploit, patch, or active‑exploitation details.

    43090369
    214 followersView on X
  • Jeff Sutherland@jeffsutherland
    Patch

    W26 read: when the agent action surface can mutate mid-session, the verifier stops being a check and starts being a vibe. CVE-2026-24763 and the flowise 9.9 are the same shape. ASF fix: HMAC-pin the tool manifest at session start. #AgentSecurity #W26

    Post summary

    The post identifies CVE‑2026‑24763 affecting Flowise 9.9 and provides a vendor fix—HMAC‑pinning the tool manifest at session start—to mitigate the issue. This is a patch advisory rather than an exploitation report.

    10020370
    49.1K followersView on X
  • もくのぶ@m_okunobu
    General

    CVE出てる!OpenClaw使ってる人早く確認して! 超簡単にいうと セキュリティ的に危ないよって報告が上がってるよってのが公開されてるよって話 CVE-2026-25253 https://nvd.nist.gov/vuln/detail/CVE-2026-25253 CVE-2026-25157 https://nvd.nist.gov/vuln/detail/CVE-2026-25157 CVE-2026-24763 https://nvd.nist.gov/vuln/detail/CVE-2026-24763 #OpenClaw

    Post summary

    The post alerts OpenClaw users that three CVE vulnerabilities have been published and advises them to verify their security status.

    00101250
    226 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-24763: HIGH] Cyber security alert: OpenClaw fixed a command injection vulnerability in its Docker sandbox. Update to version 2026.1.29 to stay secure from this risk.#cve,CVE-2026-24763,#cybersecurity https://cvefind.com/CVE-2026-24763

    Post summary

    OpenClaw identified a command injection flaw in its Docker sandbox and released version 2026.1.29 to address the risk.

    0101086
    583 followersView on X
  • Chris@mokumsgeweten1
    Disclosure

    @twistartups @MatthewBerman @JasonGrad 135,000+ OpenClaw instances are exposed to the internet. 63% vulnerable. Docker sandbox escape (CVE-2026-24763). Jason Grad told his entire company: "Do NOT install this on any work machines" — the day OpenClaw launched. The Wired article hit this week.

    Post summary

    CVE-2026-24763, a Docker sandbox escape vulnerability, has exposed over 135,000 OpenClaw instances, with 63% vulnerable to internet exposure, as highlighted in a recent Wired article.

    1000058
    43 followersView on X
  • rwsanders@rwsanders
    Disclosure

    and other people's unfavorite are kool-aid stains on a white T-Shirt. Known OpenClaw Security Issues (as of 18 Mar 2026; core engine hardened via patches in 2026.1.29–2026.3.x, but risks persist) Remote Code Execution & Command Injection: CVE-2026-25253 (CVSS 8.8, 1-click via UI token exfil/WebSocket), CVE-2026-24763 (Docker PATH/cmd injection), CVE-2026-25157 (OS command injection), plus workspace/plugin auto-discovery. Authentication & Authorization Failures: Multiple auth bypasses, scope escalation, CSRF, missing webhook validation, CVE-2026-28458 (browser relay), CVE-2026-32302 (trusted-proxy admin access). Denial of Service & Forgery: CVE-2026-28478 (webhook exhaustion), SSRF, unbounded buffering. Data Disclosure & Leaks: Plaintext API keys/credentials, local file disclosure (MEDIA tokens), cross-session exfil via prompt injection. Supply-Chain (ClawHub / ClawHavoc): 341–1,184+ malicious skills delivering stealers (Atomic Stealer, crypto/key loggers); 13.4–36.8% of scanned skills contain critical flaws; unvetted marketplace runs with full agent privileges. Exposure & Defaults: 30k–42k+ publicly exposed instances (default 0.0.0.0 bind, weak/no auth early versions). Other: Sandbox bypasses, memory poisoning, fake GitHub installers with infostealers, prompt-injection-driven unauthorized actions. Known Shortcomings (security-adjacent + functional) Insecure-by-default early design + over-privileged agent model. Impractical manual skill vetting (Lucas-highlighted scalability gap). Unpredictable autonomy (reasoning loops, task drift, stalls, silent/false completions). Steep setup & secure-configuration curve (CLI-heavy, not beginner-friendly). High resource/maintenance burden (frequent patches, memory tuning, 24/7 isolation required). Dependency on external LLMs + evolving unvetted ecosystem. Recommended immediate mitigations (actionable): Run in VM/Docker with no internet except vetted LLM endpoints; never expose publicly; install only from official/pinned verified ClawHub tier; enable any built-in VirusTotal scanning; update to latest 2026.3.x; monitor GitHub advisories.

    Post summary

    The article catalogs several OpenClaw CVEs, detailing their technical aspects, CVSS scores, and available patches, while providing mitigations but making no claims of active exploitation or PoCs.

    00000188
    282 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    OpenClaw is affected by an authenticated command injection (CVE-2026-24763) via the PATH environment variable during Docker execution. Review details. #OpenClaw #infosec #Docker https://www.pulsepatch.io/posts/cve-2026-24763-openclaw-authenticated-command-injection

    Post summary

    OpenClaw is affected by an authenticated command injection (CVE-2026-24763) triggered via the PATH variable during Docker execution; the linked PulsePatch article contains further details.

    0000097
    1 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-24763: OpenClaw Command Injection: When the PATH Leads to RCE OpenClaw (formerly Clawdbot), a self-hosted AI assistant, contained a critical OS Command Injection vulnerability in its Docker sandbox implementation. By failing to properly sanit... https://cvereports.com/reports/CVE-2026-24763

    Post summary

    A critical OS command injection flaw in OpenClaw's Docker sandbox, identified as CVE-2026-24763, has been reported with technical details but no PoC, patch, or active exploitation information.

    0000071
    27 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24763 OpenClaw Docker Sandbox Command Injection Vulnerability Before 2026.1.29 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24763

    Post summary

    The post announces a command injection vulnerability (CVE-2026-24763) in OpenClaw Docker Sandbox before version 2026.1.29, without providing PoC, exploit, or patch details.

    0000063
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-24763 OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed in OpenClaw’s Dock… https://www.cve.org/CVERecord?id=CVE-2026-24763

    Post summary

    CVE-2026-24763 is a command injection vulnerability in OpenClaw’s Dock, addressed by version 2026.1.29.

    00000154
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more