CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-FG3M-VHRR-8GJ6

GHSA-FG3M-VHRR-8GJ6: Critical Command Injection in OpenClaw Lobster Extension via Windows Shell Fallback

Amit Schendel
Amit Schendel
Senior Security Researcher

Mar 4, 2026·6 min read·32 visits

Executive Summary (TL;DR)

OpenClaw's Lobster extension on Windows contains a critical command injection flaw. If the application fails to execute the Lobster tool directly, it unsafely falls back to executing via `cmd.exe`. Attackers can exploit this by injecting shell commands into tool arguments, achieving remote code execution.

A critical OS command injection vulnerability exists in the OpenClaw "Lobster" extension when deployed on Windows systems. The vulnerability stems from an insecure fallback mechanism in the process execution logic. When the application fails to spawn the Lobster CLI tool directly (a common occurrence with Windows `.cmd` shims), it retries the operation using a system shell (`shell: true`). This fallback path does not properly sanitize user-controlled arguments, allowing authenticated attackers to inject arbitrary shell metacharacters and execute commands with the privileges of the host process. The flaw carries a CVSS score of 9.9, indicating critical impact across confidentiality, integrity, and availability.

Vulnerability Overview

The OpenClaw platform utilizes an extension architecture to integrate external tools. The "Lobster" extension specifically wraps the lobster CLI tool to perform pipeline operations. On Windows environments, npm packages are typically installed with .cmd or .bat wrapper scripts (shims) to make them executable from the command line. However, Node.js's child_process.spawn function cannot execute these batch files directly without a shell interpreter, often resulting in ENOENT or EINVAL errors when shell: false is set.

To mitigate these execution failures, the OpenClaw developers implemented a fallback mechanism. If the initial spawn attempt fails on Windows, the code catches the error and retries the execution with shell: true. While this allows the .cmd shim to run, it fundamentally changes how arguments are parsed. When shell: true is active, Node.js invokes cmd.exe /d /s /c <command>, passing the arguments as a single string to the Windows command interpreter.

This architectural decision creates a classic Command Injection vulnerability (CWE-78). Because the arguments passed to the shell include user-supplied data—specifically the pipeline name and configuration JSON—an attacker can craft inputs containing shell metacharacters (such as &, |, or >). The shell interpreter processes these characters before executing the intended command, allowing the attacker to break out of the argument context and execute arbitrary system commands.

Root Cause Analysis

The root cause lies in the unsafe error handling logic within extensions/lobster/src/lobster-tool.ts. The application prioritizes functional stability (successfully running the command) over security boundaries by dynamically enabling shell execution without sanitization.

The vulnerable logic follows this sequence:

  1. Initial Attempt: The system attempts to spawn the executable path using spawn(path, argv, { shell: false }). This is the secure default in Node.js, as it passes arguments directly to the kernel as an array, bypassing the shell.
  2. Failure Condition: On Windows, if path points to a .cmd script (common for npm global installs), the operating system fails to execute it directly, throwing an error.
  3. Insecure Fallback: The code catches this specific error and re-invokes spawn with the shell: true option enabled.

By switching to shell: true, the application delegates argument parsing to cmd.exe. In this mode, the distinction between code (the executable) and data (the arguments) is lost. The command line is constructed by concatenating the executable and arguments into a string. If the arguments contain unescaped metacharacters, cmd.exe interprets them as control operators rather than literal string data. This allows an attacker to append malicious commands that the shell executes alongside the original process.

Code Analysis

The following analysis highlights the transition from the vulnerable fallback logic to the robust shim parsing implemented in the patch.

Vulnerable Code (Pre-Patch)

In the unpatched version, the code explicitly enables the shell if the platform is Windows and a previous error occurred. Note the useShell variable which toggles the dangerous behavior.

// extensions/lobster/src/lobster-tool.ts
 
// 1. Initial spawn attempt configuration
const child = spawn(execPath, argv, {
  cwd,
  stdio: ["ignore", "pipe", "pipe"],
  env,
  shell: useShell, // DANGER: This becomes true in the fallback path
  windowsHide: useShell ? true : undefined,
});
 
// 2. The insecure fallback logic
child.on('error', async (err) => {
  if (process.platform === "win32" && isWindowsSpawnErrorThatCanUseShell(err)) {
    // If spawn failed, retry with shell: true
    return await runLobsterSubprocessOnce(params, true);
  }
});

Patched Code

The fix removes the fallback entirely. Instead, it implements resolveWindowsLobsterSpawn, which locates the actual Node.js script behind the .cmd shim and executes it directly using the current process.execPath. This maintains shell: false integrity.

// extensions/lobster/src/lobster-tool.ts (Patched)
 
// 1. Resolve the actual script entry point to avoid using shell
const { execPath: finalExecPath, args: finalArgs } = 
  await resolveWindowsLobsterSpawn(execPath, argv);
 
// 2. Spawn without shell, ensuring arguments are treated as data
const child = spawn(finalExecPath, finalArgs, {
  cwd,
  stdio: ["ignore", "pipe", "pipe"],
  env,
  shell: false, // SAFE: Shell is strictly disabled
  windowsHide: false,
});

The resolveWindowsLobsterSpawn function parses the batch file to extract the target script path, allowing OpenClaw to invoke node.exe <script> directly, bypassing the need for cmd.exe processing.

Exploitation Methodology

To exploit this vulnerability, an attacker requires authentication with sufficient privileges to invoke the Lobster tool (typically a standard user role). The attack targets the pipeline parameter in the tool invocation request.

Prerequisites

  1. Target OS: The OpenClaw instance must be running on Windows.
  2. Configuration: The configured path for the Lobster tool must point to a .cmd or .bat file (default behavior for npm installations) to trigger the spawn error and subsequent fallback.

Attack Vector

The attacker sends a crafted HTTP POST request to the tools API. The payload injects the & operator, which tells cmd.exe to execute the preceding command and then execute the following command.

POST /api/tools/invoke HTTP/1.1
Host: target-openclaw.local
Content-Type: application/json
Authorization: Bearer <user_token>
 
{
  "tool": "lobster",
  "action": "run",
  "pipeline": "dummy_pipeline & net user hacked P@ssw0rd123 /add",
  "argsJson": "{}"
}

When the vulnerable code executes this via cmd.exe /c, the effective command line becomes: lobster.cmd run dummy_pipeline & net user hacked P@ssw0rd123 /add

The system executes the Lobster tool (which may fail or run harmlessly) and immediately executes the net user command, creating a new local administrator account. Other payloads could include powershell reverse shells or data exfiltration commands.

Impact Assessment

The impact of this vulnerability is critical, categorized as CVSS 9.9. The successful exploitation results in Remote Code Execution (RCE) with the privileges of the OpenClaw service account.

Confidentiality: High. An attacker can read any file accessible to the OpenClaw process, including configuration files, environment variables containing secrets, and source code.

Integrity: High. The attacker can modify application data, overwrite system files, or install persistent backdoors (e.g., creating new users, scheduling tasks).

Availability: High. The attacker can crash the service, delete critical files, or shut down the host system, resulting in a complete denial of service.

Scope (Changed): The vulnerability is classified as Scope: Changed (S:C) because the vulnerable component (the OpenClaw application) allows the attacker to affect resources beyond its own security authority—specifically, the underlying Windows operating system. This significantly elevates the risk profile compared to a contained application compromise.

Remediation & Mitigation

The vulnerability is addressed in OpenClaw version 2026.2.23-beta.1. The patch replaces the dangerous shell fallback with a secure mechanism for resolving Windows shims.

Immediate Action: Administrators should upgrade to the patched version immediately via npm:

npm update -g openclaw

Verification: After upgrading, ensure the running version matches 2026.2.23-beta.1 or higher. Check the package.json or the application's version output.

Alternative Mitigation: If an immediate upgrade is not feasible, administrators can manually configure the lobsterPath setting to point directly to the node executable and the target JavaScript file, or an .exe binary, bypassing the .cmd shim. This prevents the initial spawn failure that triggers the vulnerable fallback path. However, this configuration change is complex and error-prone; patching is the strongly recommended solution.

Official Patches

OpenClawCommit fixing the vulnerability

Fix Analysis (1)

Technical Appendix

CVSS Score
9.9/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Systems

OpenClaw on Windows

Affected Versions Detail

Product
Affected Versions
Fixed Version
OpenClaw
OpenClaw
< 2026.2.23-beta.12026.2.23-beta.1
AttributeDetail
CWE IDCWE-78
Attack VectorNetwork
CVSS v3.19.9 (Critical)
PlatformWindows
Privileges RequiredLow (Authenticated User)
ImpactRemote Code Execution

MITRE ATT&CK Mapping

T1059.003Command and Scripting Interpreter: Windows Command Shell
Execution
T1203Exploitation for Client Execution
Execution
CWE-78
OS Command Injection

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Vulnerability Timeline

Vulnerability reported via GitHub Issue
2026-02-04
Patch committed by Peter Steinberger
2026-02-19
Disclosure and release of patched version
2026-02-22

References & Sources

  • [1]GHSA Advisory
  • [2]Issue #8514

More Reports

•about 3 hours ago•CVE-2026-92945
4.2

CVE-2026-92945: Sandbox Escape and Module Allowlist Bypass via Path Prefix Matching in vm2

A module allowlist bypass vulnerability (CVE-2026-92945 / GHSA-7q3f-wx44-378m) was identified in the vm2 sandboxing library prior to version 3.11.7. This flaw permits unauthenticated or untrusted code running within the sandbox environment to bypass explicit module restrictions. When the transitive resolution option is disabled, the system fails to validate file system path boundaries, allowing prefix-sharing sibling directories to be resolved and loaded, thereby escaping intended sandbox restrictions.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 4 hours ago•CVE-2026-92941
10.0

CVE-2026-92941: Sandbox Escape and Process-Wide TLS Trust Store Manipulation in vm2

CVE-2026-92941 is a critical sandbox-escape and trust-manipulation vulnerability in the vm2 library (versions 3.11.3 to 3.11.6). This security flaw allows untrusted code executing within a NodeVM sandbox environment to compromise the global TLS trust store of the host Node.js process. By leveraging a design flaw where the host's native 'tls.setDefaultCACertificates' can be executed via a proxy wrapper, combined with a bridge unwrapping bypass in the 'url' module, an attacker can modify the process-wide default root Certificate Authorities. Consequently, all subsequent outbound TLS/HTTPS clients running on the host thread are forced to trust attacker-signed certificates, facilitating transparent Man-in-the-Middle (MitM) attacks. The vulnerability was resolved in version 3.11.7 of vm2 by introducing built-in member-level sanitization before applying read-only proxy wrappers.

Amit Schendel
Amit Schendel
4 views•10 min read
•about 5 hours ago•CVE-2026-92944
9.8

CVE-2026-92944: Sandbox Escape in vm2 via Stale V8 PromiseThenLookupChain Protector

A critical engine-level reachability failure in Node.js 26 running V8 14.6 allows attackers to escape the vm2 sandbox environment. When consecutive prototype properties are modified using sequential assignments, a V8 optimization bug fails to invalidate the PromiseThenLookupChain protector. By calling Promise.prototype.finally, the attacker bypasses the vm2 wrappers, hijacks the promise reaction using a custom constructor, triggers a calibrated stack overflow to capture a host-realm RangeError, and executes arbitrary shell commands on the host.

Alon Barad
Alon Barad
7 views•8 min read
•about 6 hours ago•CVE-2026-92939
9.9

CVE-2026-92939: Critical Sandbox Escape via Host Crypto setEngine Native Code Execution in vm2

A critical sandbox escape vulnerability in the vm2 library allows sandboxed JavaScript code to bypass containment and execute arbitrary native code on the host process. This occurs when the host's builtin crypto module is exposed to the NodeVM environment. Although vm2 implements a read-only proxy layer to restrict direct modifications to host properties, it does not prevent invocation of host-level functions. By calling the crypto.setEngine API with a path to a malicious native library on disk, an attacker can trigger OpenSSL's dynamic module loader. The host's operating system loader immediately runs the dynamic library's initializers/constructors before verifying engine compatibility, leading to remote code execution in the context of the host process.

Amit Schendel
Amit Schendel
6 views•5 min read
•about 7 hours ago•CVE-2026-92938
9.9

CVE-2026-92938: Remote Code Execution in vm2 via node:sqlite DatabaseSync Sandbox Escape

CVE-2026-92938 is a critical sandbox escape vulnerability in the vm2 library (versions 3.11.3 through 3.11.6) that allows arbitrary native code execution on the host when the node:sqlite built-in module is loaded inside a sandboxed NodeVM environment.

Amit Schendel
Amit Schendel
8 views•8 min read
•about 8 hours ago•CVE-2026-92937
10.0

CVE-2026-92937: Sandbox Escape leading to Remote Code Execution via Promise Indirection in vm2

CVE-2026-92937 is a critical sandbox escape vulnerability in the `vm2` Node.js library. Due to a logical failure in checking direct invocation targets inside the Proxy bridge, an attacker can register Promise callbacks using `Function.prototype.call` or `Function.prototype.apply` indirection. This bypasses the error sanitization wrappers, delivering raw host error objects directly to sandboxed callbacks and allowing the attacker to escape the sandbox and execute arbitrary shell commands on the host.

Amit Schendel
Amit Schendel
8 views•6 min read