Incomplete List of Disallowed Inputs in OpenClaw - CVE-2026-32017
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to perform arbitrary file write operations.
The vulnerability exists due to incomplete list of disallowed inputs in the exec allowlist/safeBins policy when processing attached short-option payloads. A remote user can supply a specially crafted command argument to perform arbitrary file write operations.
Only configurations with tools.exec.security=allowlist and affected binaries included in tools.exec.safeBins are vulnerable.