Openclaw cli: OpenClaw's exec allow-always can be bypassed via unrecognized multiplexer shell wrappers (busybox/toybox sh -c) (CVE-2026-22175)
Description
OpenClaw CLI versions before 2026.2.23 have a vulnerability where exec approvals in allowlist mode can be bypassed using unrecognized multiplexer shell wrappers such as busybox sh -c and toybox sh -c. This occurs because the wrapper detection treated these multiplexers as non-wrappers, causing the allowlist to persist the wrapper path rather than the inner executable. This allows arbitrary payloads executed via the same multiplexer wrapper to bypass the allowlist. The issue is fixed in version 2026.2.23 by improving wrapper detection and ensuring approvals bind to the intended inner executables.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenClaw CLI's exec allowlist mechanism in allow-always mode could be bypassed when commands were executed through unrecognized multiplexer shell wrappers like busybox sh -c and toybox sh -c. The vulnerability arises because the wrapper analysis did not correctly identify these multiplexers as wrappers, causing the allowlist to store the wrapper binary path instead of the actual inner executable. Consequently, attackers could execute arbitrary payloads under the same multiplexer wrapper and bypass the allowlist restrictions. The fix, released in version 2026.2.23, hardens the detection and persistence logic to bind approvals to the correct inner executables and fail closed when the unwrap safety is uncertain.
Potential Impact
An attacker can bypass the exec allowlist in OpenClaw CLI when using unrecognized multiplexer shell wrappers, potentially allowing unauthorized execution of arbitrary commands that should have been blocked by the allowlist. This undermines the intended security control of exec approvals in allowlist mode.
Mitigation Recommendations
A patch is available and has been released in OpenClaw CLI version 2026.2.23. Users should upgrade to version 2026.2.23 or later to remediate this vulnerability. The fix improves wrapper detection and ensures that allowlist approvals correctly bind to inner executables, preventing bypass via multiplexer shell wrappers.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-22175
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac245d112601ec6a3168002
Added to database: 10/04/2026, 12:25:53 UTC
Last enriched: 10/04/2026, 13:15:26 UTC
Last updated: 10/04/2026, 16:08:36 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.