OpenClaw Exec Allowlist Bypass Vulnerability

Vulnerability

A vulnerability allowing exec allowlist bypass has been identified in OpenClaw versions prior to 2026.3.28. This issue arises because the allow-always persistence feature fails to properly unwrap wrapper binaries, such as /usr/bin/script, before recording trust decisions. As a result, attackers can manipulate user approvals for one wrapped command to gain trust for wrapper binaries that execute different underlying programs.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of programs by taking advantage of the trust granted to wrapper binaries.

Remediation

Users can upgrade to OpenClaw version 2026.3.28 or later to address this vulnerability.

Added: Apr 28, 2026, 9:25 PM
Updated: Apr 28, 2026, 9:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
2.4
remediation
0.0
relevance
6.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.