CVE-2026-28463 - Vulnerability Analysis
HighCVSS: 8.4Last Updated: March 5, 2026
OpenClaw exec-approvals - Information Disclosure
Published: March 5, 2026Updated: March 5, 2026
Overview
OpenClaw exec-approvals allowlist mode contains an information disclosure vulnerability caused by pre-expansion validation of argv tokens but real shell expansion during execution, letting authorized callers or attackers with prompt-injection read arbitrary local files, exploit requires host execution enabled in allowlist mode.
Severity & Score
Severity: High
CVSS Score: 8.4
Impact
Attackers can read arbitrary local files accessible to the gateway or node process, leading to sensitive information disclosure.
Mitigation
Disable host execution in allowlist mode or apply patches that correctly validate shell expansions; otherwise, update to the latest version.
References
Related Resources
Details
- CVE ID
- CVE-2026-28463
- Severity
- High
- CVSS Score
- 8.4
- Type
- undefined
- Status
- new
CWE
- CWE-78
CVSS Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H