CVE-2026-100559 Overview
CVE-2026-100559 is a command injection vulnerability [CWE-78] in OpenClaw versions before 2026.8.1. The command parser mishandles escaped newline sequences, allowing attackers to smuggle hidden commands past the exec allowlist. Crafted input with escaped newlines bypasses allowlist validation and executes unauthorized commands without triggering expected authorization prompts.
The flaw sits in input parsing logic that normalizes allowlist entries before execution. An attacker with low privileges can abuse this gap to run arbitrary commands within the OpenClaw execution context.
Critical Impact
Authenticated attackers can bypass command allowlist controls and execute hidden commands, resulting in high confidentiality, integrity, and availability impact on affected OpenClaw deployments.
Affected Products
- OpenClaw versions prior to 2026.8.1
- Deployments using the OpenClaw command parser with exec allowlist enforcement
- Integrations that pass untrusted input into OpenClaw command parsing
Discovery Timeline
- 2026-09-26 - CVE-2026-100559 published to NVD
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2026-100559
Vulnerability Analysis
The vulnerability lives in OpenClaw's command parser, which enforces an allowlist to constrain which commands exec may invoke. The parser fails to normalize escaped newline sequences consistently before applying allowlist checks. As a result, the allowlist validator sees one command while the executor processes additional commands appended after an escaped newline.
Exploitation requires network access and low privileges, with user interaction such as triggering a workflow that forwards attacker-controlled input into the parser. Successful exploitation grants command execution without the authorization prompts the parser would normally issue for non-allowlisted commands.
See the GitHub Security Advisory GHSA-9f86-pvv5-rxfw and the VulnCheck Command Injection Advisory for additional technical context.
Root Cause
The root cause is inconsistent parsing between the allowlist validator and the command executor. Escaped newline sequences are collapsed differently across the two code paths, producing a parser confusion condition that enables command smuggling [CWE-78].
Attack Vector
An attacker submits input containing escaped newline sequences to any surface that feeds the OpenClaw command parser. The allowlist check sees a single approved command. The executor then interprets the escaped newline as a command separator and runs the hidden trailing command without prompting for authorization.
No verified public exploit code is available. Technical details are described in prose; refer to the vendor advisory for payload specifics.
Detection Methods for CVE-2026-100559
Indicators of Compromise
- OpenClaw audit or process logs showing executed commands that were not preceded by an authorization prompt.
- Command strings in parser input containing escaped newline sequences such as \n or \r\n adjacent to allowlisted command names.
- Child processes spawned by the OpenClaw executor that do not match the allowlist configuration.
Detection Strategies
- Correlate OpenClaw parser input with executed command telemetry and flag divergence between the two.
- Alert on OpenClaw process trees that spawn shells, interpreters, or binaries outside the documented allowlist.
- Hunt for request payloads targeting OpenClaw endpoints that contain backslash-escaped control characters.
Monitoring Recommendations
- Forward OpenClaw application and audit logs to a centralized SIEM for parser-versus-executor correlation.
- Monitor outbound network connections and file writes originating from the OpenClaw service account.
- Baseline normal exec allowlist behavior and alert on deviations, including missing authorization prompt events.
How to Mitigate CVE-2026-100559
Immediate Actions Required
- Upgrade OpenClaw to version 2026.8.1 or later on all affected hosts.
- Audit recent OpenClaw command execution logs for evidence of allowlist bypass.
- Restrict network access to OpenClaw management interfaces to trusted administrators only.
- Rotate credentials and tokens accessible from the OpenClaw execution context if compromise is suspected.
Patch Information
The maintainers address the parser inconsistency in OpenClaw 2026.8.1. Review the GitHub Security Advisory GHSA-9f86-pvv5-rxfw for release notes and the VulnCheck advisory for exploitation prerequisites.
Workarounds
- Reject input containing escaped newline sequences before passing it to the OpenClaw parser.
- Tighten the exec allowlist to the minimum command set required for operations.
- Run OpenClaw under a least-privileged service account with no shell access and constrained filesystem permissions.
- Place a validating proxy or WAF rule in front of OpenClaw to strip \n, \r, and backslash-escape sequences from command parameters.
# Upgrade OpenClaw to the fixed release
# Replace with your package manager or deployment workflow
pip install --upgrade "openclaw>=2026.8.1"
# Verify installed version
openclaw --version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.