
Security advisory detailing CVE-2026-28363, a critical RCE in OpenClaw, including technical analysis, CVSS metrics, and mitigation steps for defensive purposes.
ββββββββββ βββββββββββ βββββββ βββββββ βββββββ βββββββ
βββββββββββ βββββββββββ βββββββββββββββββββββββββ ββββββββ
βββ βββ βββββββββ ββββββββββββββββ βββββββ ββββββββ
βββ ββββ ββββββββββ βββββββ ββββββββββββββββ βββββββββ
ββββββββ βββββββ ββββββββ βββββββββββββββββββββββββ βββββββββ
βββββββ βββββ ββββββββ ββββββββ βββββββ ββββββββ βββββββ
CVE-2026-28363 Β· OpenClaw Β· CVSS 9.9 CRITICAL author:https://cxsecurity.com/issue/WLB-2026030004
β οΈ NOTICE: This documentation is for informational and defensive security purposes only.
Malicious use of this information is illegal and contrary to professional ethics.
| Field | Value |
|---|---|
| CVE ID | CVE-2026-28363 |
| GHSA | GHSA-3c6h-g97w-fg78 |
| Product | OpenClaw (Node.js) |
| Affected versions | All prior to 2026.2.23 |
| Patched version | 2026.2.23 β
|
| Type | Remote Code Execution (RCE) |
| CWE | CWE-184 β Incomplete List of Disallowed Inputs |
| CVSS Score | 9.9 / 10 β CRITICAL |
The CVE-2026-28363 vulnerability resides in OpenClaw's tools.exec.safeBins validation logic. Specifically, the flaw is triggered when the sort command is used within the allowlist mode.
ATTACKER OPENCLAW SYSTEM TARGET SYSTEM
β β β
β sort --compress-prog=... β β
βββββββββββββββββββββββββββββββ>β β
β β β Validation failed β
β β (does not recognize abbreviation) β
β βββββββββββββββββββββββββββββββ>β
β β β β οΈ RCE
The system does not recognize abbreviations of GNU long options. For example:
--compress-program β recognized and correctly blocked--compress-prog β NOT recognized, bypasses validationThis difference allows an attacker to execute arbitrary code on paths the system intended to protect, completely bypassing the allowlist mechanism.
Attack Vector (AV) ββββββββββββββββββββ NETWORK
Attack Complexity (AC) ββββββββββββββββββββ LOW
Privileges Required ββββββββββββββββββββ NONE
User Interaction (UI) ββββββββββββββββββββ NONE
Scope (S) ββββββββββββββββββββ CHANGED
Confidentiality (C) ββββββββββββββββββββ HIGH
Integrity (I) ββββββββββββββββββββ HIGH
Availability (A) ββββββββββββββββββββ HIGH
FINAL SCORE: 9.9 ββββββββββββββββββββ CRITICAL
| Vector | Value | Description |
|---|---|---|
| AV | Network | Remotely exploitable over the network |
| AC | Low | Low attack complexity |
| PR | None | No prior privileges required |
| UI | None | No user interaction |
| S | Changed | Impacts beyond the vulnerable component |
| C/I/A | High | Total impact on confidentiality, integrity, and availability |
Update immediately to OpenClaw 2026.2.23 or later.
# With npm
npm update openclaw
# Verify installed version
npm list openclaw
# Update to specific version
npm install [email protected]
If updating is not possible immediately, apply the following measures in order of priority:
Monitor calls to the sort command with abbreviated options:
# Example audit rule (auditd)
auditctl -w /usr/bin/sort -p x -k openclaw_sort_watch
# Review logs in real time
ausearch -k openclaw_sort_watch -ts recent
AppArmor β restrictive profile for OpenClaw:
/usr/bin/sort {
# Deny execution with --compress-prog*
deny /usr/bin/* x,
}
SELinux β confinement policy:
# Generate confinement policy for OpenClaw
ausearch -m avc -ts recent | audit2allow -M openclaw_policy
semodule -i openclaw_policy.pp
Use the official OpenClaw Security Monitor tool to detect exploitation attempts in real time:
# Start monitor in detection mode
openclaw-monitor --watch --alert-level critical --cve CVE-2026-28363
| Version | Status | Required Action |
|---|---|---|
< 2026.2.23 | π΄ VULNERABLE | Update urgently |
>= 2026.2.23 | π’ PATCHED | No action needed |
Main affected platform: OpenClaw for Node.js
| Resource | Link |
|---|---|
| π NIST NVD | nvd.nist.gov β CVE-2026-28363 |
| π GitHub Advisory | GHSA-3c6h-g97w-fg78 |
| π¬ OpenClaw CVE Tracker | Official OpenClaw CVE tracking repository |
| π CVSS Calculator | CVSS 3.1 Calculator β FIRST |
Discovery ββββββββββββββββ Disclosure ββββββββββββββββ Patch
β β β
[Researcher] [NIST / GHSA] [v2026.2.23]
β β β
βββββββββββββββββββββββββββββββββ΄βββββββββββββββββββββββββ
Responsible disclosure process
This document is provided solely for educational and defensive purposes.
Exploiting this vulnerability on systems without explicit authorization constitutes a crime under multiple international legislations, including the Computer Fraud and Abuse Act (CFAA) in the U.S. and equivalent regulations in Latin America and Europe.If you discover this vulnerability on a production system, report it responsibly to the corresponding security team.
Keep your systems updated. Security is everyone's responsibility. π
Generated as part of a responsible security disclosure