PT-2026-26003 · Openclaw · Openclaw
Tdjackey
·
Published
2026-02-21
·
Updated
2026-03-19
·
CVE-2026-22169
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.22
Description
OpenClaw contains an allowlist bypass issue in the safeBins configuration. This allows attackers to invoke external helpers through the
compress-program option. Specifically, when sort is explicitly added to tools.exec.safeBins, remote attackers can bypass intended safe-bin approval constraints by leveraging the compress-program parameter to execute unauthorized external programs. The vulnerable component is the safeBins configuration and the vulnerable parameter is compress-program. The vulnerable function is not explicitly mentioned.Recommendations
Update OpenClaw to version 2026.2.22 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw