Junglewise Threat Intelligence

OpenClaw safeBins file-existence oracle information disclosure

Severity: low · CVSS 3.1 · Published 2026-03-12

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a command execution and system automation tool. Its safeBins feature validates which system commands are allowed to run. A flaw in this validation allows an attacker to determine whether specific files exist on the system by observing differences in how the tool responds to commands referencing existing vs. non-existing paths, enabling filesystem reconnaissance.

Technical details

The vulnerability is an observable discrepancy (CWE-203) in the safeBins file-existence handler within tools.exec component. When validating candidate file paths for command allow/deny decisions, the validation logic performed host filesystem checks, causing the approval flow to behave differently depending on whether a file path actually existed. An attacker with local access to the execution surface could probe for file presence by comparing approval outcomes between existing and non-existing filenames. The fix changed the policy to deterministic argv-only validation without file-existence checks, blocking file-oriented command flags while maintaining trusted-path enforcement. Fixed in version 2026.2.18 (commit bafdbb6f112409a65decd3d4e7350fbd637c7754).

Affected products

  • OpenClaw OpenClaw up to 2026.2.17

Timeline

  • 2026-02-19: disclosed
  • 2026-02-19: patched: Fixed in version 2026.2.18

References

Related threats