Skip to main content
Vulnerability Database/CVE-2026-100584

CVE-2026-100584: OpenClaw npm Agent Runtime RCE Vulnerability

CVE-2026-100584 is a remote code execution vulnerability in OpenClaw npm agent runtime affecting Windows hosts in exec allowlist mode. Attackers can execute arbitrary code by placing malicious executables in workspace directories. This article covers technical details, affected versions, impact analysis, and mitigation strategies.

Published:

CVE-2026-100584 Overview

CVE-2026-100584 is an allowlist bypass vulnerability in OpenClaw, an npm-distributed agent runtime. The flaw affects versions >= 2026.2.26 and < 2026.7.1 running on Windows hosts in exec allowlist mode. PowerShell command analysis approves an exact executable resolved from PATH, but subsequent execution resolves a same-named executable in the agent workspace directory. Attackers who can place a binary with an approved basename into an agent-writable workspace can execute arbitrary code with the privileges of the Gateway or node-host user. The issue is categorized as untrusted search path [CWE-426].

Critical Impact

Lower-trust content can achieve arbitrary code execution under the OpenClaw Gateway or node-host identity by shadowing allowlisted executables in agent-writable workspaces.

Affected Products

  • OpenClaw agent runtime versions >= 2026.2.26
  • OpenClaw agent runtime versions < 2026.7.1
  • Windows hosts running OpenClaw in exec allowlist mode

Discovery Timeline

  • 2026-09-26 - CVE-2026-100584 published to NVD
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-100584

Vulnerability Analysis

OpenClaw's exec allowlist mode validates PowerShell commands by resolving the referenced executable through PATH and comparing it against the approved list. The runtime then invokes the command using the bare executable name without pinning the resolved absolute path. Windows and PowerShell resolve bare names using the current working directory and PATH precedence at execution time. When the agent's working directory is a writable workspace, a same-named executable placed there is loaded instead of the allowlisted binary. The result is a time-of-check to time-of-use gap between allowlist analysis and command execution.

Root Cause

The root cause is an untrusted search path condition [CWE-426]. Allowlist validation and execution use different executable resolution contexts. Validation resolves against PATH, while execution occurs in a workspace directory that takes precedence during name resolution. The approved executable itself is never modified; the attacker only needs to add a sibling file with the same basename to the workspace.

Attack Vector

Exploitation requires local prerequisites. The attacker must have the ability to deliver content into an agent-writable workspace, which can occur through lower-trust inputs the agent processes. The attacker places an executable using the basename of an allowlisted binary into the workspace. Lower-trust content then steers the agent to issue an approved PowerShell command that references the executable by bare name. OpenClaw validates the allowlisted PATH entry but executes the workspace file, running attacker-controlled code under the Gateway or node-host user.

No verified proof-of-concept code has been published. Refer to the GitHub Security Advisory and the VulnCheck Advisory on OpenClaw for additional technical context.

Detection Methods for CVE-2026-100584

Indicators of Compromise

  • Unexpected executable files (.exe, .cmd, .bat, .ps1) appearing in OpenClaw agent workspace directories.
  • PowerShell process launches whose image path resides inside an agent workspace rather than a system PATH directory.
  • Child processes of the OpenClaw Gateway or node-host service that originate from workspace-relative paths.

Detection Strategies

  • Hunt for process creation events where the parent is the OpenClaw runtime and the child image path is under an agent workspace.
  • Compare resolved image paths of PowerShell-invoked executables against the configured allowlist of absolute paths.
  • Flag file write events that create executables with basenames matching allowlisted tools inside agent-writable directories.

Monitoring Recommendations

  • Enable Windows PowerShell script block logging and process creation auditing (Event ID 4688) with command line capture.
  • Monitor file system changes in workspace roots used by the OpenClaw Gateway and node-host accounts.
  • Alert on anomalous process lineage from the OpenClaw service account, particularly executions outside expected directories.

How to Mitigate CVE-2026-100584

Immediate Actions Required

  • Upgrade OpenClaw to version 2026.7.1 or later on all Windows hosts running in exec allowlist mode.
  • Audit existing agent workspaces for unexpected executable files and remove any that are not expected artifacts.
  • Restrict write permissions on agent workspace directories to prevent lower-trust content from placing binaries there.

Patch Information

OpenClaw version 2026.7.1 contains the fix. The patched release addresses the mismatch between allowlist validation and execution-time resolution. Review the GitHub Security Advisory GHSA-rgjw-6v73-php6 for upgrade guidance.

Workarounds

  • Avoid bare executable names in approved PowerShell commands; reference executables by absolute path.
  • Keep executable files out of agent-writable workspaces by enforcing content filters on ingested files.
  • Run the OpenClaw Gateway and node-host under least-privilege accounts to limit the impact of a successful bypass.
  • Separate the agent working directory from any directory that receives untrusted content.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.