CVE-2026-26323Disclosure(openclaw / openclaw)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtributors.ts`. The issue affects contributors/maintainers (or CI) who run `bun scripts/update-clawtributors.ts` in a source checkout that contains a malicious commit author email (e.g. crafted `@users[.]noreply[.]github[.]com` values). Normal CLI usage is not affected (`npm i -g openclaw`): this script is not part of the shipped CLI and is not executed during routine operation. The script derived a GitHub login from `git log` author metadata and interpolated it into a shell command (via `execSync`). A malicious commit record could inject shell metacharacters and execute arbitrary commands when the script is run. Version 2026.2.14 contains a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-18: 1Mentions · 2026-02-20: 1Technical Details · 2026-02-20: 102-1802-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-26323 OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtributors.ts`. The … https://www.cve.org/CVERecord?id=CVE-2026-26323

    Post summary

    The CVE‑2026‑26323 is a command injection vulnerability affecting OpenClaw versions 2026.1.8 to 2026.2.13, as disclosed in the CVE record. No exploitation or mitigation details are provided.

    00001124
    56.4K followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    Disclosure

    "The 2026 OpenClaw Vulnerability Cluster (CVE‑2026‑26323, CVE‑2026‑26327, CVE‑2026‑26317…" by gm0 #BugBounty #Cybersecurity #Hacking #InfoSec https://blog.stackademic.com/the-2026-openclaw-vulnerability-cluster-cve-2026-26323-cve-2026-26327-cve-2026-26317-188eee2cade5

    Post summary

    The post announces a cluster of new OpenClaw vulnerabilities (CVE‑2026‑26323, CVE‑2026‑26327, CVE‑2026‑26317) and links to a blog article for further details, but provides no technical, exploit, or patch information.

    0001050
    461 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more