Incomplete List of Disallowed Inputs in OpenClaw - CVE-2026-31996
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to read files or write files.
The vulnerability exists due to incomplete restriction of command arguments in tools.exec.safeBins when executing allowed safe-bin commands with sort output flags or recursive grep flags. A remote user can supply crafted command arguments to read files or write files.
Exploitation requires access to command execution flows in deployments that enabled tools.exec.safeBins.