PT-2026-26236 · Openclaw · Openclaw
Nedlir
·
Publicado
2026-02-19
·
Atualizado
2026-03-20
·
CVE-2026-31996
CVSS v2.0
6.2
Média
| Vetor | AV:L/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.19
Description
The
tools.exec.safeBins component contains an input validation bypass that allows attackers to execute unintended filesystem operations. Specifically, the issue arises when using sort output flags (like -o or --output) or recursive grep flags. Attackers with command execution access can exploit this to perform arbitrary file writes using the sort -o flag or recursive file reads using the grep -R flag, bypassing the intended stdin-only restrictions. The affected component, tools.exec.safeBins, allows for filesystem access when these flags are enabled within safe-bin execution paths.Recommendations
Update to OpenClaw version 2026.2.19 or later.
Correção
Incomplete List of Disallowed Inputs
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openclaw