{"id":"CVE-2026-31992","aliases":["GHSA-48wf-g7cp-gr3m"],"url":"https://o3.security/vulnerability/CVE-2026-31992","summary":"OpenClaw < 2026.2.23 - Allowlist Exec-Guard Bypass via env -S","details":"OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows authenticated operators to execute unintended commands. When /usr/bin/env is allowlisted, attackers can use env -S to bypass policy analysis and execute shell wrapper payloads at runtime.","published":"2026-03-19T01:00:51.216Z","modified":"2026-08-12T03:51:44.796268825Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.2.23"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/3f923e831364d83d0f23499ee49961de334cf58b","label":"openclaw/openclaw@3f923e8"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31992.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-48wf-g7cp-gr3m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31992"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-allowlist-exec-guard-bypass-via-env-s"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/3f923e831364d83d0f23499ee49961de334cf58b"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/a1c4bf07c6baad3ef87a0e710fe9aef127b1f606"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.796268825Z"}}