CVE-2026-22179
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
18/03/2026
Last modified:
25/03/2026
Description
OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute non-allowlisted commands by exploiting improper parsing of command substitution tokens. Attackers can craft shell payloads with command substitution syntax within double-quoted text to bypass security restrictions and execute arbitrary commands on the system.
Impact
Base Score 4.0
7.50
Severity 4.0
HIGH
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | 2026.2.22 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



