CVE-2026-25593 | OpenClaw up to 2026.1.19 Gateway WebSocket API config.apply cliPath os command injection (GHSA-g55j-c2v4-pjcg / EUVD-2026-5577)
A vulnerability was found in OpenClaw up to 2026.1.19. It has been rated as critical. Affected by this issue is the function config.apply of the component Gateway WebSocket API. This manipulation of the argument cliPath causes os command injection.
This vulnerability is registered as CVE-2026-25593. The attack needs to be launched locally. No exploit is available.
Upgrading the affected component is advised.