CVE-2026-31999: CpenClaw's ACPX Windows wrapper shell fallback allowed cwd injection in specific paths
(updated )
On Windows ACPX paths, wrapper resolution for .cmd/.bat could fall back to shell execution in ways that allowed cwd influence to alter execution behavior.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-31999 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →