OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansion argv tokens but executes using real shell expansion. Attackers with authorization or through prompt-injection attacks can exploit safe binaries like head, tail, or grep with glob patterns or environment variables to disclose files readable by the gateway or node process when host execution is enabled in allowlist mode.
References
Configurations
History
08 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansion argv tokens but executes using real shell expansion. Attackers with authorization or through prompt-injection attacks can exploit safe binaries like head, tail, or grep with glob patterns or environment variables to disclose files readable by the gateway or node process when host execution is enabled in allowlist mode. | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-xvhf-x56f-2hpp - Patch, Vendor Advisory |
09 Mar 2026, 17:23
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openclaw openclaw
Openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/openclaw/openclaw/commit/77b89719d5b7e271f48b6f49e334a8b991468c3b - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-xvhf-x56f-2hpp - Vendor Advisory, Patch | |
| References | () https://www.vulncheck.com/advisories/openclaw-arbitrary-file-read-via-shell-expansion-in-safe-bins-allowlist - Third Party Advisory |
09 Mar 2026, 13:36
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
05 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-05 22:16
Updated : 2026-04-08 14:16
NVD link : CVE-2026-28463
Mitre link : CVE-2026-28463
CVE.ORG link : CVE-2026-28463
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
