CVE-2026-31995Disclosure(microsoft / openclaw)

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism that allows attackers to inject arbitrary commands through tool-provided arguments. When spawn failures trigger shell fallback with shell: true, attackers can exploit cmd.exe command interpretation to execute malicious commands by controlling workflow arguments.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw
  • windows

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
openclawwindows

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-19: 2Mentions · 2026-03-20: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 103-1903-20
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-192
Disclosure1General1
2026-03-201
Disclosure1
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-31995 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-31995 #CVE-2026-31995 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/ypMJnkAdCY

    Post summary

    The tweet merely announces the existence of CVE‑2026‑31995 with a medium severity score, without providing additional details or actionable information.

    0000028
    108 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-31995 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-31995-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-31995 #openclaw #

    Post summary

    The tweet announces the CVE and links to an external article but does not provide actionable details such as PoCs, patches, or technical specifics.

    0000076
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31995 OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism that allows attac… https://www.cve.org/CVERecord?id=CVE-2026-31995

    Post summary

    The CVE-2026-31995 disclosure identifies a command injection flaw in OpenClaw’s Lobster extension for versions before 2026.2.19; the post provides technical details but no PoC, exploit, or patch information.

    0000093
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows---
Appopenclawopenclaw-node.js-

Explore more