Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-28363 β€” Security advisory detailing CVE-2026-28363, a critical RCE in OpenClaw, including technical analysis, CVSS metrics, and mitigation steps for defensive purposes. | Kitploit
Tools/GitHubGitHub/kaleth4/cve-2026-28363
Defensive ToolsVulnerability AnalysisExploitationLearning & EducationCurated Resources
GitHubkaleth4/cve-2026-28363

CVE-2026-28363

Security advisory detailing CVE-2026-28363, a critical RCE in OpenClaw, including technical analysis, CVSS metrics, and mitigation steps for defensive purposes.

View Repository
106 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

πŸ”΄ CVE-2026-28363 β€” Security Advisory

β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•—   β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—
β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•β•β•    β•šβ•β•β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ•—β•šβ•β•β•β•β–ˆβ–ˆβ•— β–ˆβ–ˆβ•”β•β•β•β•β•
β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—       β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—
β–ˆβ–ˆβ•‘     β•šβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•”β•β•β•      β–ˆβ–ˆβ•”β•β•β•β• β–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•β•  β–ˆβ–ˆβ•”β•β•β•β–ˆβ–ˆβ•—
β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•
 β•šβ•β•β•β•β•β•  β•šβ•β•β•β•  β•šβ•β•β•β•β•β•β•    β•šβ•β•β•β•β•β•β• β•šβ•β•β•β•β•β• β•šβ•β•β•β•β•β•β•  β•šβ•β•β•β•β•β•

CVE-2026-28363 Β· OpenClaw Β· CVSS 9.9 CRITICAL author:https://cxsecurity.com/issue/WLB-2026030004

Severity CVSS Status Affected

⚠️ NOTICE: This documentation is for informational and defensive security purposes only.
Malicious use of this information is illegal and contrary to professional ethics.


πŸ“‹ Executive Summary

FieldValue
CVE IDCVE-2026-28363
GHSAGHSA-3c6h-g97w-fg78
ProductOpenClaw (Node.js)
Affected versionsAll prior to 2026.2.23
Patched version2026.2.23 βœ…
TypeRemote Code Execution (RCE)
CWECWE-184 β€” Incomplete List of Disallowed Inputs
CVSS Score9.9 / 10 β€” CRITICAL

🎯 Vulnerability Description

The CVE-2026-28363 vulnerability resides in OpenClaw's tools.exec.safeBins validation logic. Specifically, the flaw is triggered when the sort command is used within the allowlist mode.

How does the flaw work?

ATTACKER                     OPENCLAW SYSTEM               TARGET SYSTEM
   β”‚                               β”‚                               β”‚
   β”‚  sort --compress-prog=...     β”‚                               β”‚
   │──────────────────────────────>β”‚                               β”‚
   β”‚                               β”‚  ❌ Validation failed         β”‚
   β”‚                               β”‚  (does not recognize abbreviation) β”‚
   β”‚                               │──────────────────────────────>β”‚
   β”‚                               β”‚                               β”‚ ⚠️ RCE

The system does not recognize abbreviations of GNU long options. For example:

  • βœ… --compress-program β†’ recognized and correctly blocked
  • ❌ --compress-prog β†’ NOT recognized, bypasses validation

This difference allows an attacker to execute arbitrary code on paths the system intended to protect, completely bypassing the allowlist mechanism.


πŸ“Š CVSS 3.1 Metrics

Attack Vector (AV)      β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ  NETWORK
Attack Complexity (AC)  β–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  LOW
Privileges Required     β–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  NONE
User Interaction (UI)   β–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  NONE
Scope (S)               β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ  CHANGED
Confidentiality (C)     β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ  HIGH
Integrity (I)           β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ  HIGH
Availability (A)        β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ  HIGH

                        FINAL SCORE: 9.9 β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ CRITICAL
VectorValueDescription
AVNetworkRemotely exploitable over the network
ACLowLow attack complexity
PRNoneNo prior privileges required
UINoneNo user interaction
SChangedImpacts beyond the vulnerable component
C/I/AHighTotal impact on confidentiality, integrity, and availability

πŸ›‘οΈ Solution and Mitigation

βœ… Primary Solution (RECOMMENDED)

Update immediately to OpenClaw 2026.2.23 or later.

# With npm
npm update openclaw

# Verify installed version
npm list openclaw

# Update to specific version
npm install [email protected]

πŸ”§ Temporary Mitigations

If updating is not possible immediately, apply the following measures in order of priority:

1. πŸ” Monitoring of Suspicious Events

Monitor calls to the sort command with abbreviated options:

# Example audit rule (auditd)
auditctl -w /usr/bin/sort -p x -k openclaw_sort_watch

# Review logs in real time
ausearch -k openclaw_sort_watch -ts recent

2. πŸ”’ Host-Level Access Control

AppArmor β€” restrictive profile for OpenClaw:

/usr/bin/sort {
  # Deny execution with --compress-prog*
  deny /usr/bin/* x,
}

SELinux β€” confinement policy:

# Generate confinement policy for OpenClaw
ausearch -m avc -ts recent | audit2allow -M openclaw_policy
semodule -i openclaw_policy.pp

3. πŸ“‘ OpenClaw Security Monitor

Use the official OpenClaw Security Monitor tool to detect exploitation attempts in real time:

# Start monitor in detection mode
openclaw-monitor --watch --alert-level critical --cve CVE-2026-28363

πŸ“¦ Affected Versions

VersionStatusRequired Action
< 2026.2.23πŸ”΄ VULNERABLEUpdate urgently
>= 2026.2.23🟒 PATCHEDNo action needed

Main affected platform: OpenClaw for Node.js


πŸ”— References and Resources

ResourceLink
πŸ“„ NIST NVDnvd.nist.gov β€” CVE-2026-28363
πŸ™ GitHub AdvisoryGHSA-3c6h-g97w-fg78
πŸ”¬ OpenClaw CVE TrackerOfficial OpenClaw CVE tracking repository
πŸ“Š CVSS CalculatorCVSS 3.1 Calculator β€” FIRST

πŸ•’ Timeline

Discovery ──────────────── Disclosure ──────────────── Patch
      β”‚                               β”‚                        β”‚
  [Researcher]              [NIST / GHSA]             [v2026.2.23]
      β”‚                               β”‚                        β”‚
      β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                      Responsible disclosure process

βš–οΈ Legal and Ethical Notice

This document is provided solely for educational and defensive purposes.
Exploiting this vulnerability on systems without explicit authorization constitutes a crime under multiple international legislations, including the Computer Fraud and Abuse Act (CFAA) in the U.S. and equivalent regulations in Latin America and Europe.

If you discover this vulnerability on a production system, report it responsibly to the corresponding security team.


Keep your systems updated. Security is everyone's responsibility. πŸ”

Generated as part of a responsible security disclosure

Download Tool