CVE-2026-55249: Command injection in @rtk-ai/rtk-rewrite OpenClaw plugin
Version 1.0.0 of the @rtk-ai/rtk-rewrite plugin for OpenClaw passes attacker-influenced exec tool command input into a shell-backed execSync() template string without shell-safe escaping, leaving $() and backtick metacharacters intact. Anyone able to influence the exec tool's command parameter, such as through an LLM agent prompt or gateway tool-call input, can achieve arbitrary OS command execution with the privileges of the plugin/gateway process.
Disclosed 23 June 2026 · Record updated 13 September 2026
Impact
Arbitrary OS command execution with the privileges of the plugin or gateway process on systems running the affected plugin version.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55249
