CVE-2026-28363: Critical severity OpenClaw vulnerability
In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was denied.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28363?
CVE-2026-28363 has been classified as a moderate severity vulnerability due to potential unauthorized execution paths.
How do I fix CVE-2026-28363?
To fix CVE-2026-28363, upgrade OpenClaw to version 2026.2.23 or later.
What are the implications of CVE-2026-28363?
The implications of CVE-2026-28363 include the risk of approving unintended command executions due to bypassed validations.
Which versions of OpenClaw are affected by CVE-2026-28363?
All versions of OpenClaw prior to 2026.2.23 are affected by CVE-2026-28363.
Can CVE-2026-28363 lead to remote code execution?
CVE-2026-28363 may potentially lead to unauthorized code execution if exploited by an attacker.