CVE Feed

    Dashboard / CVE / CVE-2026-31994

    CVE-2026-31994

    OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script generation due to unsafe handling of cmd metacharacters and expansion-sensitive characters in gateway.cmd files. Local attackers with control over service script generation arguments can inject arbitrary commands by providing metacharacter-only values or CR/LF sequences that execute unintended code in the scheduled task context.

    Published:Mar 19, 2026
    Last Modified:Mar 25, 2026
    EPS:Mar 19, 2026
    EPSS Score:0.0005
    CVSS Score:7.1

    Affected Products

    Vendor
    Microsoft
    Product
    Windows
    Vendor
    Openclaw
    Product
    Openclaw

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High