OpenClaw is an npm-distributed agent runtime. (CVE-2026-100584)
OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve an exact executable resolved from PATH but subsequently execute a same-named executable located in the workspace directory. If lower-trust content can place an executable with an approved basename into an agent-writable workspace and steer an approved PowerShell command that uses a bare executable name, OpenClaw may run the workspace file instead of the allowlisted path, executing arbitrary code with the privileges of the Gateway or node-host user. The issue does not require replacement of the approved executable itself. Version 2026.7.1 contains a fix; as a workaround, avoid bare executable names in approved PowerShell commands and keep executable files out of agent-writable workspaces.
AI Analysis
Technical Summary
The vulnerability in OpenClaw (CVE-2026-100584) affects versions >=2026.2.26 and <2026.7.1. It involves a flaw in PowerShell command analysis on Windows hosts running in exec allowlist mode. The system approves an exact executable resolved from the PATH environment but may execute a same-named executable located in the agent-writable workspace directory instead. This discrepancy allows an attacker who can place a malicious executable with an approved basename into the workspace and influence approved PowerShell commands that use bare executable names to execute arbitrary code with the privileges of the Gateway or node-host user. The vulnerability does not require replacing the approved executable itself. The issue is fixed in version 2026.7.1. A workaround is to avoid using bare executable names in approved PowerShell commands and to keep executable files out of agent-writable workspaces.
Potential Impact
Successful exploitation allows arbitrary code execution with the privileges of the Gateway or node-host user on affected Windows hosts. This can lead to full compromise of the affected system. The vulnerability requires the ability to place executables in the agent-writable workspace and to influence approved PowerShell commands using bare executable names. The CVSS v3.1 score is 6.7 (medium severity), reflecting local attack vector, high impact on confidentiality, integrity, and availability, but requiring low privileges and user interaction.
Mitigation Recommendations
Version 2026.7.1 contains a fix for this vulnerability and should be applied to affected systems. As a workaround before patching, avoid using bare executable names in approved PowerShell commands and ensure that executable files are not placed in agent-writable workspaces. No other vendor advisory or patch information is provided; check vendor sources for updates.
OpenClaw is an npm-distributed agent runtime. (CVE-2026-100584)
Description
OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve an exact executable resolved from PATH but subsequently execute a same-named executable located in the workspace directory. If lower-trust content can place an executable with an approved basename into an agent-writable workspace and steer an approved PowerShell command that uses a bare executable name, OpenClaw may run the workspace file instead of the allowlisted path, executing arbitrary code with the privileges of the Gateway or node-host user. The issue does not require replacement of the approved executable itself. Version 2026.7.1 contains a fix; as a workaround, avoid bare executable names in approved PowerShell commands and keep executable files out of agent-writable workspaces.
CVSS v3.1
Score 6.7medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in OpenClaw (CVE-2026-100584) affects versions >=2026.2.26 and <2026.7.1. It involves a flaw in PowerShell command analysis on Windows hosts running in exec allowlist mode. The system approves an exact executable resolved from the PATH environment but may execute a same-named executable located in the agent-writable workspace directory instead. This discrepancy allows an attacker who can place a malicious executable with an approved basename into the workspace and influence approved PowerShell commands that use bare executable names to execute arbitrary code with the privileges of the Gateway or node-host user. The vulnerability does not require replacing the approved executable itself. The issue is fixed in version 2026.7.1. A workaround is to avoid using bare executable names in approved PowerShell commands and to keep executable files out of agent-writable workspaces.
Potential Impact
Successful exploitation allows arbitrary code execution with the privileges of the Gateway or node-host user on affected Windows hosts. This can lead to full compromise of the affected system. The vulnerability requires the ability to place executables in the agent-writable workspace and to influence approved PowerShell commands using bare executable names. The CVSS v3.1 score is 6.7 (medium severity), reflecting local attack vector, high impact on confidentiality, integrity, and availability, but requiring low privileges and user interaction.
Mitigation Recommendations
Version 2026.7.1 contains a fix for this vulnerability and should be applied to affected systems. As a workaround before patching, avoid using bare executable names in approved PowerShell commands and ensure that executable files are not placed in agent-writable workspaces. No other vendor advisory or patch information is provided; check vendor sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qvvq-pvmc-pc5p
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100584"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ab74f26f7a7c54106e12ed6
Added to database: 09/26/2026, 04:50:46 UTC
Last enriched: 09/26/2026, 04:53:12 UTC
Last updated: 09/27/2026, 04:31:11 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.