PT-2026-27241 · Openclaw · Openclaw

Nedlir

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-32909

CVSS v3.1

3.6

Low

AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
OpenClaw before 2026.2.19 contains a command injection vulnerability in tools.exec.safeBins that allows attackers to bypass stdin-only restrictions using sort output flags or recursive grep flags. Attackers can exploit this to perform arbitrary file writes via sort -o or recursive file reads via grep -R, circumventing intended safe-bin execution restrictions.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-32909

Affected Products

Openclaw