PT-2026-26003 · Openclaw · Openclaw

·

CVE-2026-22169

·

Publicado

2026-02-21

·

Atualizado

2026-03-19

CVSS v4.0

7.1

Alta

VetorAV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.22
Description OpenClaw contains an allowlist bypass issue in the safeBins configuration. This allows attackers to invoke external helpers through the compress-program option. Specifically, when sort is explicitly added to tools.exec.safeBins, remote attackers can bypass intended safe-bin approval constraints by leveraging the compress-program parameter to execute unauthorized external programs. The vulnerable component is the safeBins configuration and the vulnerable parameter is compress-program. The vulnerable function is not explicitly mentioned.
Recommendations Update OpenClaw to version 2026.2.22 or later.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05049
CVE-2026-22169
GHSA-VMQR-RC7X-3446

Produtos afetados

Openclaw