HarborGuard / CVE
Back to search
HIGHCVE-2026-32059Published Modified CNA VulnCheck

CVE-2026-32059: OpenClaw 2026.2.22-2 < 2026.2.23 - Allowlist Bypass via sort Long-Option Abbreviation in tools.exec.safeBins

OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing attackers to bypass denied-flag checks via abbreviated options. Remote attackers can execute sort commands with abbreviated long options to skip approval requirements in allowlist mode.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
2026.2.23
Affected Products
1

Fix available

2026.2.23
Patch commits
Affected packages
  • openclaw / openclaw
    < 2026.2.23 (from 2026.2.22-2)
    Fixed in 2026.2.23
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N