CVE-2026-31995: OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Extension
OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism that allows attackers to inject arbitrary commands through tool-provided arguments. When spawn failures trigger shell fallback with shell: true, attackers can exploit cmd.exe command interpretation to execute malicious commands by controlling workflow arguments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClaw (Lobster extension)to a version that resolves this vulnerability.Fixed in 2026.2.19
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31995?
CVE-2026-31995 is considered a high-severity vulnerability due to its potential for enabling command injection.
How do I fix CVE-2026-31995?
To fix CVE-2026-31995, upgrade OpenClaw to version 2026.2.19 or later.
What systems are affected by CVE-2026-31995?
CVE-2026-31995 affects OpenClaw versions prior to 2026.2.19, specifically those utilizing the Lobster extension.
What type of vulnerability is CVE-2026-31995?
CVE-2026-31995 is a command injection vulnerability that can be exploited through the Windows shell fallback in the software.
Can CVE-2026-31995 be exploited remotely?
Yes, CVE-2026-31995 can potentially be exploited remotely by attackers to execute arbitrary commands.