Summary
A mismatch between rawCommand and command[] in the node host system.run handler could cause allowlist/approval evaluation to be performed on one command while executing a different argv.
Affected Configurations
This only impacts deployments that:
- Use the node host / companion node execution path (
system.run on a node).
- Enable allowlist-based exec policy (
security=allowlist) with approval prompting driven by allowlist misses (for example ask=on-miss).
- Allow an attacker to invoke
system.run.
Default/non-node configurations are not affected.
Impact
In affected configurations, an attacker who can invoke system.run can bypass allowlist enforcement and approval prompts by supplying an allowlisted rawCommand while providing a different command[] argv for execution.
Affected Packages / Versions
- Package:
openclaw (npm)
- Affected versions:
<= 2026.2.13
- Patched version:
>= 2026.2.14 (planned next release)
Fix
Enforce rawCommand/command[] consistency (gateway fail-fast + node host validation).
Fix Commit(s)
- cb3290fca32593956638f161d9776266b90ab891
Release Process Note
This advisory pre-sets the patched version to the planned next release (2026.2.14). Once openclaw@2026.2.14 is published to npm, the advisory can be published without further edits.
Thanks @christos-eth for reporting.
References
Summary
A mismatch between
rawCommandandcommand[]in the node hostsystem.runhandler could cause allowlist/approval evaluation to be performed on one command while executing a different argv.Affected Configurations
This only impacts deployments that:
system.runon a node).security=allowlist) with approval prompting driven by allowlist misses (for exampleask=on-miss).system.run.Default/non-node configurations are not affected.
Impact
In affected configurations, an attacker who can invoke
system.runcan bypass allowlist enforcement and approval prompts by supplying an allowlistedrawCommandwhile providing a differentcommand[]argv for execution.Affected Packages / Versions
openclaw(npm)<= 2026.2.13>= 2026.2.14(planned next release)Fix
Enforce
rawCommand/command[]consistency (gateway fail-fast + node host validation).Fix Commit(s)
Release Process Note
This advisory pre-sets the patched version to the planned next release (
2026.2.14). Onceopenclaw@2026.2.14is published to npm, the advisory can be published without further edits.Thanks @christos-eth for reporting.
References