CVE Explorer
CVE-2026-25157
OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SS
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"openclaw","vendor":"openclaw","versions":[{"status":"affected","version":"< 2026.1.29"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6f7aa30102f7848f609ed69b48ebba9b676c3c5633f1af71d35d972caa4f93ad · sha256:900a1adb4cd006a5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6f7aa30102f7848f609ed69b48ebba9b676c3c5633f1af71d35d972caa4f93ad · sha256:900a1adb4cd006a5… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-78","description":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6f7aa30102f7848f609ed69b48ebba9b676c3c5633f1af71d35d972caa4f93ad · sha256:900a1adb4cd006a5… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/openclaw/openclaw/security/advisories/GHSA-q284-4pvr-m585","tags":["x_refsource_CONFIRM"],"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-q284-4pvr-m585"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6f7aa30102f7848f609ed69b48ebba9b676c3c5633f1af71d35d972caa4f93ad · sha256:900a1adb4cd006a5… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.