Remote Code Execution Vulnerability in OpenClaw npm Package
CVE-2026-100580

8.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100580?

The OpenClaw npm package prior to version 2026.7.1 has a vulnerability that arises from improper case sensitivity handling in the model-facing cron tool. This flaw allows an actor to manipulate a tool-enabled agent to create a persistent cron job that executes arbitrary commands with the privileges of the OpenClaw process user. The exploit occurs through a mixed-case payload, which successfully bypasses the shell-execution safeguard, leading to potential unauthorized access to host files, credentials, and affecting scheduled service availability. The risk is confined to cron jobs managed via the model-facing cron tool, as direct command line interface and authorized Gateway scheduling are considered secure operator controls. The vulnerability has been addressed in version 2026.7.1.

Affected Version(s)

OpenClaw 0 < 2026.7.1

OpenClaw 2026.7.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

shayd-versa
.