OpenClaw Allowlist Bypass Vulnerability via Sort Compression Program Flag

Vulnerability

A vulnerability allowing allowlist bypass has been identified in OpenClaw versions prior to 2026.2.22. This issue arises in the safe-bin configuration when the 'sort' command is manually added to 'tools.exec.safeBins'. In this scenario, attackers can exploit the '--compress-program' flag to execute arbitrary external programs without operator approval. This bypass occurs in allowlist mode with 'ask=on-miss' enabled, allowing the unauthorized execution of programs under the OpenClaw process context.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of external programs within the OpenClaw process, bypassing established approval mechanisms.

Reproduction

To reproduce this vulnerability, manually add 'sort' to the 'tools.exec.safeBins' configuration. Then, in an environment where 'security' is set to 'allowlist' and 'ask' is enabled, invoke the 'sort' command with the '--compress-program' flag. This will bypass the allowlist approval process and execute the specified program.

Remediation

Users can update to OpenClaw version 2026.2.22 or later, where this vulnerability has been patched.

Added: Mar 19, 2026, 10:47 PM
Updated: Mar 19, 2026, 10:47 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.8
remediation
0.0
relevance
4.1
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.