MEDIUM
OpenClaw File Existence tools.exec.safeBins information exposure
Published Mar 12, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.20%
Description
A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handler. The manipulation leads to information exposure through discrepancy. The attack needs to be performed locally. Upgrading to version 2026.2.19-beta.1 is capable of addressing this issue. The identifier of the patch is bafdbb6f112409a65decd3d4e7350fbd637c7754. Upgrading the affected component is advised.
Affected products
-
- Version 2026.2.0StatusaffectedConstraints-
- Version 2026.2.1StatusaffectedConstraints-
- Version 2026.2.10StatusaffectedConstraints-
- Version 2026.2.11StatusaffectedConstraints-
- Version 2026.2.12StatusaffectedConstraints-
- Version 2026.2.13StatusaffectedConstraints-
- Version 2026.2.14StatusaffectedConstraints-
- Version 2026.2.15StatusaffectedConstraints-
- Version 2026.2.16StatusaffectedConstraints-
- Version 2026.2.17StatusaffectedConstraints-
- Version 2026.2.2StatusaffectedConstraints-
- Version 2026.2.3StatusaffectedConstraints-
- Version 2026.2.4StatusaffectedConstraints-
- Version 2026.2.5StatusaffectedConstraints-
- Version 2026.2.6StatusaffectedConstraints-
- Version 2026.2.7StatusaffectedConstraints-
- Version 2026.2.8StatusaffectedConstraints-
- Version 2026.2.9StatusaffectedConstraints-
- Version 2026.2.19-beta.1StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Openclaw | OpenClaw | n/a |
|
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.2.19
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.2.19 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (10)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-11565 Advisory
- https://github.com/advisories/GHSA-6c9j-x93c-rw6j Advisory
- https://github.com/openclaw/openclaw/ product
- https://github.com/openclaw/openclaw/commit/bafdbb6f112409a65decd3d4e7350fbd637c7754 patch
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.19-beta.1 patchRelease Notes
- https://github.com/openclaw/openclaw/security/advisories/GHSA-6c9j-x93c-rw6j relatedVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-4040
- https://vuldb.com/?ctiid.350652 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.350652 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.769581 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-11565 | Advisory | |
| https://github.com/advisories/GHSA-6c9j-x93c-rw6j | Advisory | |
| https://github.com/openclaw/openclaw/ | product | |
| https://github.com/openclaw/openclaw/commit/bafdbb6f112409a65decd3d4e7350fbd637c7754 | patch | |
| https://github.com/openclaw/openclaw/releases/tag/v2026.2.19-beta.1 | patchRelease Notes | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-6c9j-x93c-rw6j | relatedVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-4040 | ||
| https://vuldb.com/?ctiid.350652 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.350652 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.769581 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 12, 2026
Updated Mar 12, 2026
Reserved Mar 12, 2026
Link CVE-2026-4040
CISA Vulnrichment
Updated Mar 12, 2026
ENISA EUVD
EUVD-2026-11565 GHSA-6C9J-X93C-RW6J Assigner VulDB
Published Mar 12, 2026
Updated Mar 12, 2026
Exploited since n/a
Link EUVD-2026-11565