CVE-2026-29610 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating PATH environ…
High CVSS: 7.7

CVE-2026-29610

OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating PATH environment variables through node-host execution or project-local bootstrapping. Attackers with authenticated access to node-host execution surfaces or those running OpenClaw in attacker-controlled directories can place malicious executables in PATH to override allowlisted safe-bin commands and achieve arbitrary command execution.
Vendor
Openclaw
Product
Openclaw
CWE
CWE-427
Yayın Tarihi
2026-03-05 22:16:24
Güncelleme
2026-03-11 01:02:58
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar