PT-2026-26236 · Openclaw · Openclaw

Nedlir

·

Publicado

2026-02-19

·

Atualizado

2026-03-20

·

CVE-2026-31996

CVSS v2.0

6.2

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.19
Description The tools.exec.safeBins component contains an input validation bypass that allows attackers to execute unintended filesystem operations. Specifically, the issue arises when using sort output flags (like -o or --output) or recursive grep flags. Attackers with command execution access can exploit this to perform arbitrary file writes using the sort -o flag or recursive file reads using the grep -R flag, bypassing the intended stdin-only restrictions. The affected component, tools.exec.safeBins, allows for filesystem access when these flags are enabled within safe-bin execution paths.
Recommendations Update to OpenClaw version 2026.2.19 or later.

Correção

Incomplete List of Disallowed Inputs

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05007
CVE-2026-31996
GHSA-4685-C5CP-VP95
GHSA-GGM6-H3MX-CMMP

Produtos afetados

Openclaw