Advisory · CVE-2026-101880
OpenClaw Windows Node approval bypass smuggles commands through pipes and substitutions
The exec-approval shell unwrapper fails to split pipeline stages and command substitutions, so a benign allow rule silently approves and executes a smuggled command on the Windows host.
- Vendor
- openclaw
- Product
- OpenClaw Windows Node
- Identifier / CWE
- CVE-2026-101880
CWE-863, CWE-184 - Action timing
- Immediate
Explain it like I’m five
The agent asks permission before running each command, but it only reads the outside of the box. An attacker can hide a command inside the box using a pipe or a dollar-parenthesis trick, and the checker waves the whole box through.
- 01Benign outer command
A connected gateway or agent calls system.run with a command matching a benign allow rule, such as echo * or Get-ChildItem *.
- 02Hidden stage
The command embeds a denied command behind a pipeline operator (|) or a command substitution ($( ... ) or backticks).
- 03Unwrapper misses it
ExecShellWrapperParser.Expand splits on ;, &&, and || but never isolates single-| pipeline stages or substitution spans, so the smuggled command is never surfaced for approval.
- 04Silent execution
The outer allow rule auto-approves with no prompt, and the real shell executes the hidden command, including the node's shipped default deny rules (e.g. net *) which never fire.
What happened
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy. The policy unwraps shell wrappers with ExecShellWrapperParser.Expand so that each embedded command is evaluated against allow and deny rules. The unwrapper splits top-level command chains on ;, &, &&, and ||, but it does not split the pipeline operator | (only the logical OR ||), and it does not extract $(...) or backtick command-substitution spans at all.
Because system.run executes the approved command through a real shell (powershell.exe -Command or cmd.exe /C), those operators are interpreted at execution time. A caller can smuggle a denied command inside a pipeline stage or a substitution, for example echo $(Remove-Item -Recurse $HOME) or Get-ChildItem C:/Windows/Temp/x | Remove-Item -Recurse -Force, and the smuggled command is never surfaced as an evaluation target. An anchored deny rule never fires while a benign allow rule on the outer string auto-approves with no prompt, not even the node’s shipped default denylist.
The flaw is rated high at CVSS 8.8 and is fixed in OpenClaw Windows Node 2026.7.1.
What to do
- Inventory Windows nodes running OpenClaw Windows Node before 2026.7.1.
- Upgrade to v2026.7.1 or later.
- Review exec-approval rule sets for any broad allow rules added while the node was vulnerable.
- Inspect command execution history for pipeline or substitution syntax in auto-approved commands.
- Treat any node that was reachable by a lower-trust gateway or agent as potentially compromised and review the host accordingly.
Management note
This is a guardrail-defeat bug in an AI agent’s permission boundary, the exact control that is supposed to contain a prompt-injected or compromised agent. The approval gate looked intact while silently waving through hidden commands. Patching is only half the job: any permissive rules or unexpected command history created while the node was exposed must be treated as attacker-influenced until proven otherwise.