OpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool Execution
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.8epss 0.6%
probabilidad de explotación
0.6%top 54% de las CVE
explotación observada
noninguna fuente lo reporta
OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallback with shell: true after spawn failures. Attackers can inject shell metacharacters in command arguments to execute arbitrary commands when subprocess launch fails with EINVAL or ENOENT errors.
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
OpenClaw · OpenClaw