CVE-2026-32016: OpenClaw < 2026.2.22 - Path Traversal via Basename-Only Allowlist Matching on macOS
OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowlist mode that allows local attackers to execute unauthorized binaries by exploiting basename-only allowlist entries. Attackers can execute same-name local binaries ./echo without approval when security=allowlist and ask=on-miss are configured, bypassing intended path-based policy restrictions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.2.22
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32016?
CVE-2026-32016 has been rated as a high-severity vulnerability due to its impact on system security.
How do I fix CVE-2026-32016?
To fix CVE-2026-32016, upgrade OpenClaw to version 2026.2.22 or later.
What type of vulnerability is CVE-2026-32016?
CVE-2026-32016 is a path traversal vulnerability that allows unauthorized execution of binaries.
Who is affected by CVE-2026-32016?
CVE-2026-32016 affects users running OpenClaw versions prior to 2026.2.22 on macOS.
Can CVE-2026-32016 be exploited remotely?
CVE-2026-32016 cannot be exploited remotely as it requires local access to the system.