Improper Neutralization of Argument Delimiters in a Command in OpenClaw - CVE-2026-28463
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper neutralization of special elements in the exec approvals allowlist validation for safe bins when executing commands through a real shell with shell expansion. A remote user can supply crafted tokens such as glob patterns or environment variable references to disclose sensitive information.
The issue is configuration-dependent and requires host execution to be enabled with tools.exec.host=gateway|node and security=allowlist; default settings are not affected.