CVE-2026-28463Disclosure(openclaw / openclaw)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansion argv tokens but executes using real shell expansion. Attackers with authorization or through prompt-injection attacks can exploit safe binaries like head, tail, or grep with glob patterns or environment variables to disclose files readable by the gateway or node process when host execution is enabled in allowlist mode.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-06); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-06: 2Mentions · 2026-03-07: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0603-07
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-062
Disclosure2
2026-03-071
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-28463 OpenClaw exec-approvals allowlist validation checks pre-expansion argv tokens but execution uses real shell expansion, allowing safe bins like head, tail, or grep to … https://www.cve.org/CVERecord?id=CVE-2026-28463

    Post summary

    The text discloses a command injection flaw in OpenClaw where pre‑expansion allowlist checks allow real shell expansion of safe binaries, implying potential remote code execution.

    00000153
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28463 - High OpenClaw exec-approvals allowlist validation checks pre-expansion argv tokens but execution uses real shell expansion, allowing safe bins like head, tail, or grep to read arbitrary local file... https://www.thehackerwire.com/vulnerability/CVE-2026-28463/ https://t.co/1EiDBzG2TX

    Post summary

    The tweet announces a new high‑severity CVE‑2026‑28463, detailing a flaw in OpenClaw’s exec‑approval validation that allows benign binaries to read arbitrary local files through shell expansion.

    0000077
    125 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-28463 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-28463-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-28463 #openclaw #

    Post summary

    A brief CVE alert for CVE-2026-28463 affecting OpenClaw is shared with a reference link, but no further technical, exploit, or mitigation information is provided.

    00000114
    3.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more