Untrusted search path in OpenClaw - CVE-2026-32009
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to untrusted search path in safeBins allowlist mode when resolving executables from static default trusted directories. A local user can place a same-name binary in a trusted writable directory to execute arbitrary code.
Exploitation requires the ability to write into a trusted host binary directory.