CVE-2026-29610
OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating PATH environment variables through node-host execution or project-local bootstrapping. Attackers with authenticated access to node-host execution surfaces or those running OpenClaw in attacker-controlled directories can place malicious executables in PATH to override allowlisted safe-bin commands and achieve arbitrary command execution.
- Affected products
- Openclaw
- Openclaw
- < 2026.2.14
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.5% (38th percentile)
- Weakness
- CWE-427
- NVD status
- Analyzed
- Published
- 2026-03-05
CVE-2026-29610 at NVD
No indexed exploits for CVE-2026-29610 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-29610 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.