PT-2026-22291 · Openclaw · Openclaw
Tdjackey
·
Published
2026-02-27
·
Updated
2026-03-04
·
CVE-2026-28363
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.23
Description
The software contains a validation bypass in the
tools.exec.safeBins logic for the sort command. This bypass occurs when using GNU long-option abbreviations (such as --compress-prog) in allowlist mode, allowing execution paths that should require approval to run without it. The vulnerable component is the tools.exec.safeBins function.Recommendations
Update OpenClaw to version 2026.2.23 or later.
Fix
LPE
Incomplete List of Disallowed Inputs
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw