Skip to main content

Openclaw cli: OpenClaw's tools.exec.safeBins trusted PATH directories allowed binary shadowing in allowlist mode

0
High
Published: 08/13/2026 (08/13/2026, 17:21:32 UTC)
Source: GCVE Database
Product: openclaw-cli

Description

OpenClaw CLI in allowlist mode trusted PATH-derived directories for safe binary execution, allowing an attacker to bypass the allowlist by placing a same-name binary in a trusted directory. This could lead to command execution within the OpenClaw runtime context. The vulnerability affects openclaw versions up to 2026.2.21-2 and is planned to be fixed in version 2026.2.22. The root cause is trusting PATH-derived directories instead of explicit trusted directories and using shell command tokens that could resolve to shadowed binaries.

CVSS v4.0

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected software

Homebrewmore threats →ghsa
openclaw-cli
pkg:brew/openclaw-cli
Affected versions
<2026.7.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/04/2026, 12:30:02 UTC

Technical Analysis

In openclaw CLI's allowlist mode, the tools.exec.safeBins feature trusted directories derived from the PATH environment variable for resolving safe binaries. This allowed an attacker to place a malicious binary with the same name in a trusted PATH directory, bypassing the allowlist and enabling command execution in the OpenClaw runtime context. The vulnerability exists in versions <= 2026.2.21-2 and is addressed by removing trust in PATH-derived directories, introducing explicit trusted directory configuration (tools.exec.safeBinTrustedDirs), and pinning safe-bin execution to resolved absolute executable paths. The fix is planned for release in version 2026.2.22.

Potential Impact

An attacker who can influence the location of binaries in trusted PATH directories can bypass the allowlist execution policy, leading to unauthorized command execution within the OpenClaw runtime environment. This compromises the security guarantees of the allowlist mode by allowing execution of potentially malicious binaries.

Mitigation Recommendations

A patch is available and planned for release in version 2026.2.22. Users should upgrade to this version once released. The fix removes trust in PATH-derived directories for safe-bin resolution, requires explicit configuration of trusted directories, and ensures execution uses absolute resolved paths. Until the patch is applied, users should avoid relying on allowlist mode with safeBins in environments where untrusted binaries could be placed in PATH directories.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-openclaw-cli-GHSA-qhrr-grqp-6x2g
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
4.0

Threat ID: 6ac2458312601ec6a3164074

Added to database: 10/04/2026, 12:24:35 UTC

Last enriched: 10/04/2026, 12:30:02 UTC

Last updated: 10/04/2026, 12:30:02 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses