top of page
perceptive_background_267k.jpg

OpenClaw exec-approvals allowlist validation checks pre-expansion argv tokens but execution uses real shell expansion, allowing safe bins like head, tail, or gr…

Published:

4 maart 2026 om 23:00:00

Alert date:

5 maart 2026 om 23:13:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools, Web Technologies

OpenClaw exec-approvals component has a vulnerability where allowlist validation checks pre-expansion argv tokens but execution uses real shell expansion. This allows attackers to exploit safe binaries like head, tail, or grep to read arbitrary local files via glob patterns or environment variables. The vulnerability can be exploited by authorized callers or through prompt-injection attacks when host execution is enabled in allowlist mode. This leads to disclosure of files readable by the gateway or node process, presenting a significant security risk for systems running OpenClaw with host execution enabled.

Technical details

Mitigation steps:

Affected products:

OpenClaw

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page