Openclaw cli: OpenClaw's tools.exec.safeBins trusted PATH directories allowed binary shadowing in allowlist mode
Description
OpenClaw CLI in allowlist mode trusted PATH-derived directories for safe binary execution, allowing an attacker to bypass the allowlist by placing a same-name binary in a trusted directory. This could lead to command execution within the OpenClaw runtime context. The vulnerability affects openclaw versions up to 2026.2.21-2 and is planned to be fixed in version 2026.2.22. The root cause is trusting PATH-derived directories instead of explicit trusted directories and using shell command tokens that could resolve to shadowed binaries.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In openclaw CLI's allowlist mode, the tools.exec.safeBins feature trusted directories derived from the PATH environment variable for resolving safe binaries. This allowed an attacker to place a malicious binary with the same name in a trusted PATH directory, bypassing the allowlist and enabling command execution in the OpenClaw runtime context. The vulnerability exists in versions <= 2026.2.21-2 and is addressed by removing trust in PATH-derived directories, introducing explicit trusted directory configuration (tools.exec.safeBinTrustedDirs), and pinning safe-bin execution to resolved absolute executable paths. The fix is planned for release in version 2026.2.22.
Potential Impact
An attacker who can influence the location of binaries in trusted PATH directories can bypass the allowlist execution policy, leading to unauthorized command execution within the OpenClaw runtime environment. This compromises the security guarantees of the allowlist mode by allowing execution of potentially malicious binaries.
Mitigation Recommendations
A patch is available and planned for release in version 2026.2.22. Users should upgrade to this version once released. The fix removes trust in PATH-derived directories for safe-bin resolution, requires explicit configuration of trusted directories, and ensures execution uses absolute resolved paths. Until the patch is applied, users should avoid relying on allowlist mode with safeBins in environments where untrusted binaries could be placed in PATH directories.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-GHSA-qhrr-grqp-6x2g
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac2458312601ec6a3164074
Added to database: 10/04/2026, 12:24:35 UTC
Last enriched: 10/04/2026, 12:30:02 UTC
Last updated: 10/04/2026, 12:30:02 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.