PT-2026-26236 · Openclaw · Openclaw

·

CVE-2026-31996

·

Published

2026-02-19

·

Updated

2026-03-20

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.19
Description The tools.exec.safeBins component contains an input validation bypass that allows attackers to execute unintended filesystem operations. Specifically, the issue arises when using sort output flags (like -o or --output) or recursive grep flags. Attackers with command execution access can exploit this to perform arbitrary file writes using the sort -o flag or recursive file reads using the grep -R flag, bypassing the intended stdin-only restrictions. The affected component, tools.exec.safeBins, allows for filesystem access when these flags are enabled within safe-bin execution paths.
Recommendations Update to OpenClaw version 2026.2.19 or later.

Exploit

Fix

Incomplete List of Disallowed Inputs

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05007
CVE-2026-31996
GHSA-4685-C5CP-VP95
GHSA-GGM6-H3MX-CMMP

Affected Products

Openclaw