CVE-2026-22179: OpenClaw < 2026.2.22 - Allowlist Bypass via Command Substitution in system.run
OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute non-allowlisted commands by exploiting improper parsing of command substitution tokens. Attackers can craft shell payloads with command substitution syntax within double-quoted text to bypass security restrictions and execute arbitrary commands on the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.2.22
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22179?
CVE-2026-22179 is considered a high severity vulnerability that allows attackers to bypass the allowlist and execute arbitrary commands.
How do I fix CVE-2026-22179?
To fix CVE-2026-22179, upgrade OpenClaw to version 2026.2.22 or later.
What type of vulnerability is CVE-2026-22179?
CVE-2026-22179 is an allowlist bypass vulnerability that can be exploited via command substitution.
What consequences can arise from CVE-2026-22179?
Exploitation of CVE-2026-22179 may lead to unauthorized command execution by remote attackers.
Which versions of OpenClaw are affected by CVE-2026-22179?
OpenClaw versions prior to 2026.2.22 are affected by CVE-2026-22179.