OpenClaw Approval Bypass Vulnerability in system.run Allowing Executable Rebind

Vulnerability

An approval bypass vulnerability has been identified in OpenClaw versions prior to 2026.3.1. This vulnerability exists in the system.run feature, where non-path-like argv[0] tokens do not properly bind executable identity. As a result, attackers can exploit this flaw by modifying PATH resolution after an action has been approved, allowing them to execute a different binary than what was originally authorized.

Impact

Exploitation of this vulnerability could lead to the execution of an unauthorized binary, bypassing the original approval process.

Remediation

Users can upgrade to OpenClaw version 2026.3.1 or later to address this vulnerability.

Added: Mar 23, 2026, 10:25 PM
Updated: Mar 23, 2026, 10:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
2.4
remediation
0.0
relevance
4.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.