CVE-2026-32010: Openclaw
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exec.safeBins. Attackers can invoke sort with the --compress-program flag to execute arbitrary external programs without operator approval in allowlist mode with ask=on-miss enabled.
Affected products
- Openclaw Openclaw: before 2026.2.22 (fixed in 2026.2.22)
Published 2026-03-19. Last modified 2026-06-17.