
Cloud Vulnerability DB
A community-led vulnerabilities database
Discovered: 2026-02-04 Reporter: @akhmittra
OpenClaw previously accepted untrusted PATH sources in limited situations. In affected versions, this could cause OpenClaw to resolve and execute an unintended binary ("command hijacking") when running host commands.
This issue primarily matters when OpenClaw is relying on allowlist/safe-bin protections and expects PATH to be trustworthy.
openclaw (npm)< 2026.2.14>= 2026.2.14 (planned next release)An attacker needs all of the following:
system.run).system.run.PATH) into system.run.PATH (for example, a writable directory on the node host), with a name that matches an allowlisted/safe-bin command that OpenClaw will run.
Notes:An attacker needs all of the following:
node_modules/.bin/openclaw and additional attacker-controlled executables in the same directory.PATH) that matches one of those attacker-controlled executables.node_modules/.bin PATH bootstrapping is now disabled by default. If explicitly enabled, it is append-only (never prepended) via OPENCLAW_ALLOW_PROJECT_LOCAL_BIN=1.PATH overrides.Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."