OpenClaw exec allowlist/safeBins policy could be bypassed with attached short-option payloads (for example sort -o/tmp/poc), enabling file-write operations while still satisfying safeBins checks.
openclaw (npm)<= 2026.2.172026.2.172026.2.19When tools.exec.security=allowlist and tools.exec.safeBins included affected binaries, attached short-option payloads could bypass safeBins argument validation and permit file-write behavior that should have been denied.
OpenClaw thanks @FailButWin and @Redgrave961 for reporting.
{
"github_reviewed": true,
"github_reviewed_at": "2026-03-03T21:48:29Z",
"severity": "MODERATE",
"nvd_published_at": "2026-03-19T22:16:35Z",
"cwe_ids": [
"CWE-184"
]
}