Remote Code Execution Vulnerability in OpenClaw npm Package
CVE-2026-100580
What is CVE-2026-100580?
The OpenClaw npm package prior to version 2026.7.1 has a vulnerability that arises from improper case sensitivity handling in the model-facing cron tool. This flaw allows an actor to manipulate a tool-enabled agent to create a persistent cron job that executes arbitrary commands with the privileges of the OpenClaw process user. The exploit occurs through a mixed-case payload, which successfully bypasses the shell-execution safeguard, leading to potential unauthorized access to host files, credentials, and affecting scheduled service availability. The risk is confined to cron jobs managed via the model-facing cron tool, as direct command line interface and authorized Gateway scheduling are considered secure operator controls. The vulnerability has been addressed in version 2026.7.1.
Affected Version(s)
OpenClaw 0 < 2026.7.1
OpenClaw 2026.7.1
