๐Ÿ” CVE Alert

CVE-2026-32017

HIGH 7.1

OpenClaw < 2026.2.19 - Arbitrary File Write via Short-Option Bypass in exec Allowlist

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
13th

OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that allows attackers to write arbitrary files using short-option payloads. Attackers can bypass argument validation by attaching short options like -o to whitelisted binaries, enabling unauthorized file-write operations that should be denied by safeBins checks.

CWE CWE-184
Vendor openclaw
Product openclaw
Published Mar 19, 2026
Last Updated Mar 25, 2026
Stay Ahead of the Next One

Get instant alerts for openclaw openclaw

Be the first to know when new high vulnerabilities affecting openclaw openclaw are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
Low

Affected Versions

OpenClaw / OpenClaw
0 < 2026.2.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openclaw/openclaw/security/advisories/GHSA-3x3x-h76w-hp98 github.com: https://github.com/openclaw/openclaw/commit/cfe8457a0f4aae5324daec261d3b0aad1461a4bc github.com: https://github.com/openclaw/openclaw/commit/bafdbb6f112409a65decd3d4e7350fbd637c7754 github.com: https://github.com/openclaw/openclaw/commit/fec48a5006eab37c6a5821726ccaeec886486b13 vulncheck.com: https://www.vulncheck.com/advisories/openclaw-arbitrary-file-write-via-short-option-bypass-in-exec-allowlist

Credits

๐Ÿ” xelitte (@FailButWin) ๐Ÿ” Redgrave961