CVE-2026-31996

MEDIUM

OpenClaw < 2026.2.19 - safeBins stdin-only bypass via sort output and recursive grep flags

Title source: cna
STIX 2.1

Description

OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that allows attackers to execute unintended filesystem operations through sort output flags or recursive grep flags. Attackers with command execution access can leverage sort -o flag for arbitrary file writes or grep -R flag for recursive file reads, circumventing intended stdin-only restrictions.

Scores

CVSS v3 4.4
EPSS 0.0001
EPSS Percentile 3.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-78
Status published
Products (4)
npm/openclaw 0 - 2026.2.19npm
OpenClaw/OpenClaw < 2026.2.19
openclaw/openclaw < 2026.2.19
OpenClaw/OpenClaw 2026.2.19
Published Mar 19, 2026
Tracked Since Mar 19, 2026