CVE-2026-100580: OpenClaw before 2026.7.1 Remote Code Execution via cron tool

Published Sep 26, 2026
·
Updated

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool-enabled agent can therefore create a persistent cron job that executes attacker-selected commands with the privileges of the OpenClaw process user, resulting in access to host files and credentials and impact to scheduled service availability. The issue is limited to cron jobs created or edited through the model-facing cron tool; direct CLI and authorized Gateway scheduling surfaces are trusted operator controls. Fixed in 2026.7.1.

Affected Software

1 affected component
npm/openclaw<2026.7.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/openclaw to a version that resolves this vulnerability.

    Fixed in 2026.7.1

Event History

Sep 26, 2026
CVE Published
via MITRE·02:19 AM
Data Sourced
via MITRE·02:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness
Mar 6, 58707
Event
via NVD·05:23 PM

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be able to steer a tool-enabled OpenClaw agent. They can use a mixed-case payload kind through the model-facing cron tool to bypass the shell-execution guard and create or modify a command job.

2

Are direct CLI or Gateway scheduling workflows affected?

No. The issue is limited to cron jobs created or edited through the model-facing cron tool; direct CLI and authorized Gateway scheduling surfaces are described as trusted operator controls.

3

What is the impact of successful exploitation?

A successful attacker can establish a persistent cron job that runs attacker-selected commands as the OpenClaw process user. This can expose host files and credentials and disrupt scheduled service availability.

4

What should teams do if they cannot update immediately?

Limit untrusted parties' ability to steer tool-enabled agents, particularly where those agents can access the model-facing cron tool. Review cron jobs created or edited through that tool for unexpected command jobs.

5

Which version contains the fix?

The issue is fixed in OpenClaw version 2026.7.1. Versions before 2026.7.1 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203