CVE-2026-26325Disclosure(openclaw / openclaw)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the node host `system.run` handler could cause allowlist/approval evaluation to be performed on one command while executing a different argv. This only impacts deployments that use the node host / companion node execution path (`system.run` on a node), enable allowlist-based exec policy (`security=allowlist`) with approval prompting driven by allowlist misses (for example `ask=on-miss`), allow an attacker to invoke `system.run`. Default/non-node configurations are not affected. Version 2026.2.14 enforces `rawCommand`/`command[]` consistency (gateway fail-fast + node host validation).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-18); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-18: 4Mentions · 2026-02-20: 1Mentions · 2026-03-01: 1Patch / Workaround · 2026-02-18: 2Technical Details · 2026-02-18: 3Technical Details · 2026-03-01: 102-1802-2003-01
Signal classification3 categories
Disclosure
233.3%
Patch
233.3%
General
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-184
Disclosure2Patch2
2026-02-201
General1
2026-03-011
General1
Full discourse6 posts
  • Cantina 🪐@cantinaxyz
    Disclosure

    Status: High-severity vulnerability found by Cantina’s AI Code Analyzer in @OpenClaw (CVE-2026-26325). Our AI engine detected an allowlist bypass in OpenClaw's npm package. The flaw allows a mismatch between checked commands and executed commands. Full breakdown below: https://t.co/60nxmMzGep

    Post summary

    A new high‑severity allowlist bypass vulnerability (CVE‑2026‑26325) was discovered in OpenClaw’s npm package by Cantina’s AI Code Analyzer, with a brief technical breakdown linked in the tweet.

    2135692512.8K
    18.5K followersView on X
  • Spearbit@spearbit
    Patch

    Our AI Code Analyzer at Cantina just flagged a high vulnerability in the @OpenClaw npm package (CVE-2026-26325). The team promptly acknowledged and patched it. Early access to our tool is here: https://cantina.review/cantinacode787b04

    Post summary

    The announcement notes a high vulnerability (CVE-2026-26325) in the @OpenClaw npm package and confirms that the team has acknowledged and patched it.

    0301942.6K
    14.1K followersView on X
  • Apogee | DevSecOps Web3@0xApogee
    Disclosure

    High severity vulnerability in #OpenClaw (CVE-2026-26325) @cantinaxyz has discovered an allowlist bypass in the OpenClaw npm package. Because of this, the commands verified by the system may not match the actual executed commands. This creates a risk of executing unwanted commands and compromising security.

    Post summary

    The post announces a high‑severity allowlist bypass in the OpenClaw npm package that could allow execution of arbitrary commands.

    02030101
    91 followersView on X
  • Coyote Security Scanner@CoyoteSecure
    General

    Okay, Sunday morning dev session complete, here's what we built this morning 💪🐺 Expand OpenClaw security coverage by implementing ten new CVE checks in the existing version and precondition analyzer model, with full test and doc updates. Added CVE checks: - CVE-2026-26324 (SSRF IPv4-mapped IPv6 guard bypass) - CVE-2026-26325 (http://system.run rawCommand/argv mismatch bypass) - CVE-2026-26316 (BlueBubbles webhook auth bypass) - CVE-2026-26326 (skills.status secret disclosure) - CVE-2026-27003 (Telegram token log exposure) - CVE-2026-27009 (Control UI stored XSS) - CVE-2026-26320 (deep-link prompt truncation/social engineering) - CVE-2026-27487 (macOS keychain refresh command injection) - CVE-2026-27486 (cleanup cross-process termination) - CVE-2026-27485 (skill packager symlink file disclosure) Implementation details: - Extend `_CVE_FIX_VERSIONS` with new fixed-version thresholds. - Add recursive config string/pattern helpers for indicator detection. - Add all new checks to `OpenClawSecurityAnalyzer.analyze(...)`. - Extend `_build_cve_check(...)` with optional `min_affected_version` handling for range-sensitive CVEs (used by CVE-2026-26320). - Keep existing status semantics: VULNERABLE/WARNING/SAFE/UNKNOWN. Tests: - Expand `tests/test_openclaw_security.py` to validate: - new CVE presence - version-threshold behavior - patched-version risky-config WARNING behavior - UNKNOWN behavior for all tracked CVEs Docs: - Update README OpenClaw coverage from 5 to 15 CVEs. - Add all new CVEs to "OpenClaw CVEs Covered" and "Checks Performed" tables. - Refresh OpenClaw example summary text. - Rewrite http://OpenClawCVEs.md with full 15-CVE coverage and per-check logic. Validation: - `python3 -m unittest tests/test_openclaw_security.py` (pass) - `python3 -m unittest discover -s tests` (pass, 31 tests)

    Post summary

    The post announces a development update adding new CVE checks to OpenClaw, listing the CVEs and their brief descriptions, but does not mention PoC, exploit code, active exploitation, patches, or false positives.

    20010192
    225 followersView on X
  • Mike Leffer@mikeleffer
    Patch

    We just disclosed a High-Severity vulnerability in @openclaw (CVE-2026-26325). If you are running `system(.)run` in a Node host configuration, you need to pay attention. Here is the immediate operational checklist: **1.** Search your manifests for `openclaw` package versions **2026.2.13** or older. If you find them, assume any `http://system.run` call is a potential bypass vector. **2.** The maintainers have released **v2026.2.14, which fixed the problem**. As a general rule, always update the software; more & more bugs are being fixed every day. **3.** Stop relying on regex for command validation. If your security check looks at Variable A, but your execution engine runs Variable B, you have a logic gap. **4.** Static analysis is great for syntax, but it fails at intent. We built our AI tool specifically to catch these "logic decouplings", where the code *looks* right but *acts* wrong. This CVE is just the tip of the iceberg. Our engine flagged **5 distinct vulnerabilities** in this single audit. We will release details on the other four findings shortly.

    Post summary

    The text announces CVE-2026-26325 in openclaw, explains the issue, and provides the patch version v2026.2.14 to mitigate the vulnerability.

    00030369
    1.1K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26325 OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the node host `http://system.run` handler could cause all… https://www.cve.org/CVERecord?id=CVE-2026-26325

    Post summary

    The excerpt notes a mismatch issue in OpenClaw’s command handling for CVE-2026-26325, but offers no concrete PoC, exploit, or patch details.

    00000105
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more