HIGH
OpenClaw 2026.1.21 < 2026.2.19 - PATH Hijacking Bypass in tools.exec.safeBins Allowlist Validation
Published Mar 19, 2026
7.3
HIGHCVSS 4.0
EPSS 0.18%
Description
OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows attackers to bypass allowlist checks by controlling process PATH resolution. Attackers who can influence the gateway process PATH or launch environment can execute trojan binaries with allowlisted names, such as jq, circumventing executable validation controls.
Affected products
-
- Version 2026.1.21StatusaffectedConstraints<2026.2.19
- Version 2026.2.19StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 2026.1.21 Fixed 2026.2.19
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 2026.1.21 | 2026.2.19 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://github.com/advisories/GHSA-g75x-8qqm-2vxp Advisory
- https://github.com/openclaw/openclaw/commit/28bac46c92069dc728524fbf383024c1b64e5c23 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-g75x-8qqm-2vxp vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-32015
- https://www.vulncheck.com/advisories/openclaw-path-hijacking-bypass-in-tools-exec-safebins-allowlist-validation third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-g75x-8qqm-2vxp | Advisory | |
| https://github.com/openclaw/openclaw/commit/28bac46c92069dc728524fbf383024c1b64e5c23 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-g75x-8qqm-2vxp | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-32015 | ||
| https://www.vulncheck.com/advisories/openclaw-path-hijacking-bypass-in-tools-exec-safebins-allowlist-validation | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 19, 2026
Updated Jun 23, 2026
Reserved Mar 10, 2026
Link CVE-2026-32015
CISA Vulnrichment
GHSA-G75X-8QQM-2VXP Updated Mar 20, 2026