


Perceptive Security
SOC/SIEM Consultancy

OpenClaw exec-approvals allowlist validation checks pre-expansion argv tokens but execution uses real shell expansion, allowing safe bins like head, tail, or gr…
Published:
4 maart 2026 om 23:00:00
Alert date:
5 maart 2026 om 23:13:13
Source:
nvd.nist.gov
Security Tools, Web Technologies
OpenClaw exec-approvals component has a vulnerability where allowlist validation checks pre-expansion argv tokens but execution uses real shell expansion. This allows attackers to exploit safe binaries like head, tail, or grep to read arbitrary local files via glob patterns or environment variables. The vulnerability can be exploited by authorized callers or through prompt-injection attacks when host execution is enabled in allowlist mode. This leads to disclosure of files readable by the gateway or node process, presenting a significant security risk for systems running OpenClaw with host execution enabled.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-28463
https://github.com/openclaw/openclaw/commit/77b89719d5b7e271f48b6f49e334a8b991468c3b
https://github.com/openclaw/openclaw/security/advisories/GHSA-xvhf-x56f-2hpp
https://www.vulncheck.com/advisories/openclaw-arbitrary-file-read-via-shell-expansion-in-safe-bins-allowlist
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
