Security Advisory

CVE-2026-29608

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-19 01:00:48
Last updated 2026-06-23 16:14:18
Assigner VulnCheck
State PUBLISHED

Description

OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting changes command semantics. Attackers can place malicious local scripts in the working directory to execute unintended code despite operator approval of different command text.