Incomplete List of Disallowed Inputs in OpenClaw - #VU128784
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass safe-bin restrictions.
The vulnerability exists due to incomplete list of disallowed inputs in safe-bin argument validation and allowlist evaluation when processing GNU long-option abbreviations. A remote attacker can supply a specially crafted abbreviated long option to bypass safe-bin restrictions.
This can create a policy and runtime mismatch where denied options are approved during validation but resolved differently at runtime.