Junglewise Threat Intelligence

CVE-2026-32009: OpenClaw safeBins allowlist bypass via writable default directories

CVE-2026-32009 · Severity: low · CVSS 3.1 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI automation tool that executes commands on systems. The safeBins feature is meant to restrict which executable binaries can be run, functioning as a security policy. Due to overly permissive default trusted directories (like /opt/homebrew/bin and /usr/local/bin) that are typically writable, an attacker with local write access can place a malicious binary with the same name as an approved executable and trick the system into running it, bypassing the security policy.

Technical details

The vulnerability is an untrusted search path (CWE-426) and inclusion of untrusted functionality (CWE-829) affecting OpenClaw's safeBins policy mechanism. The root cause is that the allowlist evaluation relies on directory membership alone for determining trust, without validating the immutability or proper ownership of those directories. When a binary is requested (e.g., jq), OpenClaw resolves it by searching the static default trusted directories; if an attacker has write access to one of those directories (e.g., via package manager write permissions), they can place a malicious binary there. The trust decision succeeds based on directory membership, allowing execution of the attacker-controlled binary. The fix restricts default safe-bin trusted directories to immutable system paths (/bin, /usr/bin) and requires explicit operator opt-in for package-manager paths via a configuration option. Patch version 2026.2.24 (released 2026-02-25) contains the fix.

Affected products

  • OpenClaw openclaw ≤2026.2.23

Timeline

  • 2026-02-25: disclosed: Advisory published; version 2026.2.24 with fix released on npm
  • 2026-02-25: patched: openclaw@2026.2.24 published on npm

References