Junglewise Threat Intelligence

CVE-2026-32059: OpenClaw is vulnerable to validation bypass through GNU long-option abbreviations in allowlist mode

CVE-2026-32059 · Severity: low · CVSS 3.1 · Published 2026-02-27

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a tool execution system that can be configured to restrict which commands and flags are allowed. When running in allowlist mode with execution approval enabled, an attacker with local or network access could bypass the security restrictions for the "sort" command by using abbreviated long options (e.g., --compress-prog instead of --compress-program). This allows executing commands that would normally require explicit approval, potentially enabling arbitrary code execution on systems relying on these controls.

Technical details

The vulnerability exists in OpenClaw's safeBins validation logic for the sort command when operating in allowlist mode with approval enabled (tools.exec.security=allowlist and tools.exec.ask=on-miss). The root cause is that the long-option handler matched denied flags by exact string comparison and incorrectly accepted unknown long options with inline values instead of implementing fail-closed validation. An attacker can craft abbreviated GNU long options (e.g., --compress-prog as an abbreviation of --compress-program, or --files0 for --files0-from) that bypass the denied-flag checks for dangerous options like --compress-program, --files0-from, --temporary-directory, and --random-source. This requires network or local access and valid credentials (PR:L per CVSS), but no user interaction. The attacker can achieve high impact on confidentiality, integrity, and availability. The vulnerability was fixed in version 2026.2.23 by implementing fail-closed long-option validation that rejects unknown flags and ambiguous abbreviations.

Affected products

  • OpenClaw openclaw <= 2026.2.22-2, fixed in 2026.2.23

CVE identifiers

  • CVE-2026-32059
  • CVE-2026-28363

Timeline

  • 2026-03-03: disclosed: GHSA-3c6h-g97w-fg78 published
  • 2026-02-23: patched: Fix committed; version 2026.2.23 released with hardened long-option validation

References

Related threats