Duplicate Advisory: safeBins stdin-only bypass via sort output and recursive grep flags
Low severity
GitHub Reviewed
Published
Mar 19, 2026
to the GitHub Advisory Database
•
Updated Mar 19, 2026
Withdrawn
This advisory was withdrawn on Mar 19, 2026
Description
Published by the National Vulnerability Database
Mar 19, 2026
Published to the GitHub Advisory Database
Mar 19, 2026
Reviewed
Mar 19, 2026
Withdrawn
Mar 19, 2026
Last updated
Mar 19, 2026
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-4685-c5cp-vp95. This link is maintained to preserve external references.
Original Description
OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that allows attackers to execute unintended filesystem operations through sort output flags or recursive grep flags. Attackers with command execution access can leverage sort -o flag for arbitrary file writes or grep -R flag for recursive file reads, circumventing intended stdin-only restrictions.
References