
CVE-2026-28463 OpenClaw exec-approvals allowlist validation checks pre-expansion argv tokens but execution uses real shell expansion, allowing safe bins like head, tail, or grep to … https://www.cve.org/CVERecord?id=CVE-2026-28463
Post summary
The text discloses a command injection flaw in OpenClaw where pre‑expansion allowlist checks allow real shell expansion of safe binaries, implying potential remote code execution.


