Incomplete List of Disallowed Inputs in OpenClaw - CVE-2026-32010
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to run an external program without expected approval.
The vulnerability exists due to incomplete list of disallowed inputs in the sort safe-bin policy when processing sort --compress-program in safe-bin usage. A remote user can supply a crafted sort invocation with --compress-program to run an external program without expected approval.
Only deployments that explicitly add sort to tools.exec.safeBins and use security=allowlist with ask=on-miss are vulnerable.