OpenClaw Input Validation Bypass Vulnerability in SafeBins Tool Execution

Vulnerability

A vulnerability allowing input validation bypass has been identified in OpenClaw versions prior to 2026.2.19, specifically within the tools.exec.safeBins component. This vulnerability enables attackers to execute unintended filesystem operations by exploiting sort output flags or recursive grep flags. In environments where command execution is permitted, the sort -o flag can be used for arbitrary file writing, while the grep -R flag allows for recursive file reading, bypassing the intended restriction of stdin-only input.

Impact

Exploitation of this vulnerability could lead to unauthorized filesystem modifications or disclosures, depending on the flags used.

Remediation

Users can upgrade to OpenClaw version 2026.2.19 or later to address this vulnerability.

Added: Mar 19, 2026, 2:22 AM
Updated: Mar 19, 2026, 2:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
6.7
exploitability
5.9
remediation
0.0
relevance
4.1
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.