CVE-2026-100559: OpenClaw before 2026.8.1 Command Injection via Escaped Newlines
OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.8.1
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation is network-accessible but requires low-level privileges and user interaction. An attacker must be able to submit crafted input containing escaped newlines.
What is the potential impact of successful exploitation?
A successful attacker can bypass exec allowlist validation and run additional hidden commands without the expected authorization prompts. The reported impact includes high confidentiality, integrity, and availability effects.
How can I determine whether an installation is affected?
OpenClaw versions before 2026.8.1 are affected. Installations running 2026.8.1 or later are not identified as affected by the provided advisory information.