CVE-2026-22169
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, remote attackers can bypass intended safe-bin approval constraints by leveraging the compress-program parameter to execute unauthorized external programs.
Vendor
Product
CWE
Yayın Tarihi
2026-03-18 02:16:20
Güncelleme
2026-03-25 15:16:35
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-