CVE-2026-29610
OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating PATH environment variables through node-host execution or project-local bootstrapping. Attackers with authenticated access to node-host execution surfaces or those running OpenClaw in attacker-controlled directories can place malicious executables in PATH to override allowlisted safe-bin commands and achieve arbitrary command execution.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.46%
- CWE
- CWE-427
- Published
- 2026-03-05
- Last modified
- 2026-03-16
Affected products
- OpenClaw OpenClaw
Weakness type
Related vulnerabilities
- CVE-2019-25268 — NREL BEopt 2.8.0 Insecure Library Loading Arbitrary Code Execution
- CVE-2025-65118 — AVEVA Process Optimization Uncontrolled Search Path Element
- CVE-2025-13051 — Windows service used an uncontrolled search path element will cause unauthorized code execution with localsystem privileges
- CVE-2026-87530 — Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a l
- CVE-2025-30248 — DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker t
- CVE-2026-24502 — Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerabilit
- CVE-2025-33208 — NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path.
- CVE-2026-28456 — OpenClaw 2026.1.5 < 2026.2.14 - Arbitrary Code Execution via Unsafe Hook Module Path Handling