Description
OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in approved commands to read unintended node-local files and expose sensitive configuration data.
Problem types
Time-of-check Time-of-use (TOCTOU) Race Condition
Product status
Any version before 2026.5.18
2026.5.18 (semver)
Credits
cantinagen
Ellahi (@Ellahinator)
References
github.com/...enclaw/security/advisories/GHSA-mhq8-78pj-5j79 (GitHub Security Advisory (GHSA-mhq8-78pj-5j79))
www.vulncheck.com/...ansion-in-system-run-safe-bin-allowlist (VulnCheck Advisory: OpenClaw < 2026.5.18 - Arbitrary File Read via Shell Expansion in system.run Safe-bin Allowlist)