Incomplete List of Disallowed Inputs in OpenClaw - CVE-2026-31996

 

Incomplete List of Disallowed Inputs in OpenClaw - CVE-2026-31996

Published: May 4, 2026


Vulnerability identifier: #VU129418
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31996
CWE-ID: CWE-184
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read files or write files.

The vulnerability exists due to incomplete restriction of command arguments in tools.exec.safeBins when executing allowed safe-bin commands with sort output flags or recursive grep flags. A remote user can supply crafted command arguments to read files or write files.

Exploitation requires access to command execution flows in deployments that enabled tools.exec.safeBins.


Affected software

OpenClaw

How to mitigate CVE-2026-31996

Install security update from vendor's website.

OpenClaw - update to 2026.2.19

External References

Related Security Bulletins