CVE-2026-32059Disclosure(openclaw / openclaw)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing attackers to bypass denied-flag checks via abbreviated options. Remote attackers can execute sort commands with abbreviated long options to skip approval requirements in allowlist mode.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-11); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-12: 1Mentions · 2026-03-15: 1Mentions · 2026-03-17: 1Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-15: 1Technical Details · 2026-03-11: 3Technical Details · 2026-03-15: 103-1103-1203-1503-17
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclosure3
2026-03-121
General1
2026-03-151
Disclosure1
2026-03-171
General1
Full discourse6 posts
  • IntegSec@integ_sec
    General

    CVE-2026-32059: OpenClaw Allowlist Bypass Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q047dGQj0

    Post summary

    The snippet only lists the CVE name and a link, offering no concrete technical, exploit, or mitigation details.

    0000043
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32059 OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing att… https://www.cve.org/CVERecord?id=CVE-2026-32059

    Post summary

    CVE-2026-32059 describes a validation failure in OpenClaw's sort command that could allow remote command injection, with the issue fixed in version 2026.2.23.

    00000121
    56.7K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-32059 - openclaw - openclaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-32059-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-32059 #openclaw #

    Post summary

    The tweet links to a CVE alert for CVE‑2026‑32059 but provides no technical details, PoC, exploit tool, active exploitation evidence, or patch information.

    0000094
    3.5K followersView on X
  • botnewsnetwork@botnewsnetwork
    Disclosure

    🚨 THE ATTACK SURFACE WIDENED OVERNIGHT: NEW OPENCLAW CVEs, RUST SUPPLY CHAIN, CHINA'S SECOND WARNING Two new HIGH severity CVEs disclosed today: → CVE-2026-32060: Path traversal in apply_patch — write or delete files outside your workspace. Patch: 2026.2.14+ → CVE-2026-32059: GNU long-option bypass in safeBins sort validation. Patch: 2026.2.22-2+ Endor Labs audited OpenClaw independently: 6 additional vulnerabilities found — SSRF, missing authentication, more path traversal. This is a sustained audit wave, not isolated bugs. Supply chain now hitting developer toolchain (CVE-2026-28353): 5 malicious Rust crates on http://crates.io targeting AI coding CLIs — delivered via weaponized Open VSX extension (v1.8.12-1.8.13). After npm (14K downloads) and ClawHub (341 skills), attackers are inside the IDE extension layer. China's CNCERT/CC just issued its second OpenClaw advisory in 72 hours — following MIIT's Monday warning. Now the national cybersecurity coordination center is flagging prompt injection, insufficient permissions, and default config data leaks. The 72-hour escalation: → npm supply chain → ClawHub (341 compromised skills) → Two new core CVEs → Rust crate toolchain attack → Two nation-state advisories Every layer is live. Update OpenClaw now. Audit every extension and crate in your build chain. #BNN #AgentSecurity #OpenClaw #CVE #SupplyChain

    Post summary

    The post announces two new high-severity CVEs in OpenClaw, lists their patches, details technical aspects, and highlights related supply‑chain threats, but does not provide PoC, exploit code, or proof of active exploitation.

    0000040
    25 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32059: HIGH] Cybersecurity Alert: OpenClaw 2026.2.22-2 allows remote attackers to execute unauthorized sort commands by exploiting validation flaws in GNU long-option abbreviations. Update to versi...#cve,CVE-2026-32059,#cybersecurity https://cvefind.com/CVE-2026-32059

    Post summary

    The alert announces CVE-2026-32059, a high‑severity flaw in OpenClaw that allows remote command execution via flawed GNU long‑option parsing, and recommends updating to a patched version.

    0000047
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32059 - High OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing attackers to bypass denied-f... https://www.thehackerwire.com/vulnerability/CVE-2026-32059/ https://t.co/mOd3ChGaIJ

    Post summary

    The tweet discloses a high‑severity vulnerability (CVE‑2026‑32059) in OpenClaw that lets attackers bypass sort command restrictions by exploiting improper long‑option validation in tools.exec.safeBins.

    0000041
    134 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more