CVE-2026-28460
OpenClaw's system.run allowlist bypass via shell line-continuation command substitution
描述
### Summary In OpenClaw `system.run` allowlist mode, shell-wrapper analysis could be bypassed by splitting command substitution as `$\\` + newline + `(` inside double quotes. Analysis treated the payload as allowlisted (for example `/bin/echo`), while shell runtime folded the line continuation into `$(...)` and executed non-allowlisted subcommands. ### Affected Packages / Versions - Package: npm `openclaw` - Latest published affected version: `2026.2.21-2` - Affected range: `<=2026.2.21-2` - Patched version (planned next release): `2026.2.22` ### Impact In deployments that opt into `tools.exec.security=allowlist` (with `ask=on-miss` or `off`), this can bypass approval boundaries and lead to unintended command execution. ### Fix Commit(s) - `3f0b9dbb36c86e308267924c0d3d4a4e1fc4d1e9` ### Remediation - Upgrade to `2026.2.22` (or newer) when published. - Temporary mitigation: set `tools.exec.ask=always` or `tools.exec.security=deny`. ### Release Process Note `patched_versions` is pre-set to planned next release `2026.2.22`. After npm release is out, this advisory should be ready for direct publish without additional metadata edits. OpenClaw thanks @tdjackey for reporting.
如何修補 CVE-2026-28460
要修補 CVE-2026-28460,請將受影響套件升級到下列已修補版本。
- —升級至 2026.2.22 或更新版本
CVE-2026-28460 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2026.2.22