High priorityDisclosed

Advisory · CVE-2026-101880

OpenClaw Windows Node approval bypass smuggles commands through pipes and substitutions

The exec-approval shell unwrapper fails to split pipeline stages and command substitutions, so a benign allow rule silently approves and executes a smuggled command on the Windows host.

Vendor
openclaw
Product
OpenClaw Windows Node
Identifier / CWE
CVE-2026-101880
CWE-863, CWE-184
Action timing
Immediate
ELI5

Explain it like I’m five

The agent asks permission before running each command, but it only reads the outside of the box. An attacker can hide a command inside the box using a pipe or a dollar-parenthesis trick, and the checker waves the whole box through.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Benign outer command

    A connected gateway or agent calls system.run with a command matching a benign allow rule, such as echo * or Get-ChildItem *.

  2. 02Hidden stage

    The command embeds a denied command behind a pipeline operator (|) or a command substitution ($( ... ) or backticks).

  3. 03Unwrapper misses it

    ExecShellWrapperParser.Expand splits on ;, &&, and || but never isolates single-| pipeline stages or substitution spans, so the smuggled command is never surfaced for approval.

  4. 04Silent execution

    The outer allow rule auto-approves with no prompt, and the real shell executes the hidden command, including the node's shipped default deny rules (e.g. net *) which never fire.

What happened

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy. The policy unwraps shell wrappers with ExecShellWrapperParser.Expand so that each embedded command is evaluated against allow and deny rules. The unwrapper splits top-level command chains on ;, &, &&, and ||, but it does not split the pipeline operator | (only the logical OR ||), and it does not extract $(...) or backtick command-substitution spans at all.

Because system.run executes the approved command through a real shell (powershell.exe -Command or cmd.exe /C), those operators are interpreted at execution time. A caller can smuggle a denied command inside a pipeline stage or a substitution, for example echo $(Remove-Item -Recurse $HOME) or Get-ChildItem C:/Windows/Temp/x | Remove-Item -Recurse -Force, and the smuggled command is never surfaced as an evaluation target. An anchored deny rule never fires while a benign allow rule on the outer string auto-approves with no prompt, not even the node’s shipped default denylist.

The flaw is rated high at CVSS 8.8 and is fixed in OpenClaw Windows Node 2026.7.1.

What to do

  1. Inventory Windows nodes running OpenClaw Windows Node before 2026.7.1.
  2. Upgrade to v2026.7.1 or later.
  3. Review exec-approval rule sets for any broad allow rules added while the node was vulnerable.
  4. Inspect command execution history for pipeline or substitution syntax in auto-approved commands.
  5. Treat any node that was reachable by a lower-trust gateway or agent as potentially compromised and review the host accordingly.

Management note

This is a guardrail-defeat bug in an AI agent’s permission boundary, the exact control that is supposed to contain a prompt-injected or compromised agent. The approval gate looked intact while silently waving through hidden commands. Patching is only half the job: any permissive rules or unexpected command history created while the node was exposed must be treated as attacker-influenced until proven otherwise.