CVE-2026-22217: Openclaw
Medium severity, CVSS 6.1. EPSS: 0.1% chance of exploitation in the next 30 days.
OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allows attackers to execute attacker-controlled binaries by exploiting trusted-prefix fallback logic for the $SHELL variable. An attacker can influence the $SHELL environment variable on systems with writable trusted-prefix directories such as /opt/homebrew/bin to execute arbitrary binaries in the OpenClaw process context.
Affected products
- Openclaw Openclaw: from 2026.2.22, before 2026.2.23 (fixed in 2026.2.23)
Published 2026-03-18. Last modified 2026-06-17.