PT-2026-26403 · Openclaw · Openclaw
Athul Jayaram
·
Published
2026-03-19
·
Updated
2026-03-19
·
CVE-2026-32022
CVSS v3.1
5.3
Medium
| AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec.safeBins that allows attackers to read arbitrary files by supplying a pattern via the -e flag parameter. Attackers can include a positional filename operand to bypass file access restrictions and read sensitive files .env from the working directory.
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw