<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:openclaw:windows_node:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aopenclawwindows_node/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 20:36:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aopenclawwindows_node/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in OpenClaw Windows Node via Command Injection</title><link>https://feed.craftedsignal.io/briefs/2026-09-openclaw-auth-bypass/</link><pubDate>Wed, 30 Sep 2026 20:36:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-openclaw-auth-bypass/</guid><description>An incorrect authorization vulnerability in OpenClaw Windows Node version &lt; 2026.7.1 allows unauthenticated agents to achieve arbitrary command execution by bypassing command approval policies.</description><content:encoded><![CDATA[<p>OpenClaw Windows Node version 2026.7.1 and earlier contains an incorrect authorization vulnerability in the system.run exec-approval policy. The vulnerability resides within the ExecShellWrapperParser component, which fails to correctly tokenize or sanitize input commands. Specifically, the parser does not properly handle pipe operators or command substitution syntax, allowing a malicious or compromised gateway/agent to append denied commands to otherwise authorized prefixes. By exploiting this parsing logic, an attacker can bypass defined approval rules, leading to unauthorized arbitrary command execution on the host operating system. This issue poses a high risk to organizations relying on OpenClaw for automated system management and task execution.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary code execution on systems running the OpenClaw Windows Node. This can lead to full system compromise, lateral movement within the environment, and exfiltration of sensitive data, depending on the privileges of the service account running the OpenClaw node agent.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update all instances of OpenClaw Windows Node to version 2026.7.1 or later immediately. Review audit logs for system.run command executions that contain pipe characters or command substitution syntax to identify potential prior exploitation attempts.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>command-injection</category><category>execution</category></item></channel></rss>