Junglewise Threat Intelligence

OpenClaw tools.exec.safeBins interpreter payload execution in allowlist mode

Severity: medium · CVSS 4 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a node.js library for safely executing external commands. A misconfiguration flaw in its allowlist mode allows an operator to inadvertently add interpreter binaries (Python, Node, Ruby, etc.) to a safe-bin list, which then permits inline code execution via command-line flags like -c. This affects only non-default deployments where an operator explicitly configures such binaries, limiting practical impact.

Technical details

The vulnerability is a protection mechanism bypass (CWE-693) and OS command injection (CWE-78) in OpenClaw's tools.exec.safeBins module. When a binary was added to safeBins without an explicit safe-bin profile, the library fell back to a permissive generic profile that failed to block interpreter-style inline execution flags. In allowlist mode, this allowed binaries like python3, node, and ruby to execute arbitrary code via flags such as -c. The attack requires an operator to explicitly misconfigure the safeBins list with an interpreter binary, and no user interaction is required beyond that initial setup. The fix (version 2026.2.22+) removes the generic fallback and requires explicit safe-bin profiles for all safeBins entries.

Affected products

  • OpenClaw openclaw <= 2026.2.21-2

Timeline

  • 2026-03-03: disclosed
  • 2026-02-22: patched: Fix commit 47c3f742b6c488be26dd7b9636dbbb8676089154
  • 2026-03-03: advisory: GHSA-8mf7-vv8w-hjr2

References

Related threats