CVE-2026-31997: OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind
(updated )
For host=node runs, approvals validated command context but did not pin executable identity for non-path-like argv[0] tokens (for example tr). If PATH resolution changed after approval, execution could run a different binary.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-31997 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →