PT-2026-24669 · Git+2 · Openclaw

Tdjackey

·

Published

2026-02-27

·

Updated

2026-03-17

·

CVE-2026-32059

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.2.22-2 through 2026.2.22-2
Description The tools.exec.safeBins validation for the sort command does not properly validate GNU long-option abbreviations. This allows attackers to bypass denied-flag checks using abbreviated options. Remote attackers can execute sort commands with abbreviated long options to skip approval requirements when operating in allowlist mode. The issue occurs when tools.exec.security is set to allowlist, tools.exec.ask is set to on-miss, and tools.exec.safeBins includes sort. Long-option handling matched denied flags by exact string and accepted unknown long options with inline values instead of failing closed.
Recommendations Update OpenClaw to version 2026.2.23 or later.

Fix

Incomplete List of Disallowed Inputs

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32059
GHSA-3C6H-G97W-FG78
GHSA-7977-C43C-XPWJ

Affected Products

Openclaw