Junglewise Threat Intelligence

CVE-2026-28463: OpenClaw exec approvals safeBins shell expansion bypass

CVE-2026-28463 · Severity: low · CVSS 3.1 · Published 2026-02-18

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a tool for managing secure command execution with approval workflows. When configured to use host execution with an allowlist, a security bypass allows attackers to read arbitrary files by exploiting shell expansion (glob patterns and environment variables) to circumvent the intended stdin-only constraints on certain commands. This could lead to unauthorized disclosure of sensitive files accessible to the gateway or node process.

Technical details

The vulnerability is a command injection security bypass (CWE-78) in OpenClaw's exec-approvals allowlist validation. The allowlist checks argument tokens before shell expansion, but the actual execution uses a real shell (sh -c), which expands globs (*) and environment variables ($HOME, etc.). This allows safe bins like head, tail, or grep to read arbitrary local files via crafted tokens without triggering approvals. Attack requires tools.exec.host to be set to gateway or node (not the default sandbox), and the caller must be authorized. The fix (v2026.2.14+) forces safe-bin arguments to be treated as literal text using single-quoting, preventing expansion at execution time.

Affected products

  • OpenClaw OpenClaw <= 2026.2.13

Timeline

  • 2026-02-18: disclosed: Advisory published on GitHub
  • 2026-02-14: patched: Fix commit 77b89719d5b7e271f48b6f49e334a8b991468c3b
  • 2026-02-14: other: Reported by christos-eth

References

Related threats