CVE-2026-4040
OpenClaw safeBins file-existence oracle information disclosure
描述
An information disclosure vulnerability in OpenClaw's `tools.exec.safeBins` approval flow allowed a file-existence oracle. When safe-bin validation examined candidate file paths, command allow/deny behavior could differ based on whether a path already existed on the host filesystem. An attacker could probe for file presence by comparing outcomes for existing vs non-existing filenames. ## Affected Packages / Versions - Package: `openclaw` (npm) - Affected versions: `<= 2026.2.17` - Latest published vulnerable version at triage time: `2026.2.17` - Planned patched version: `2026.2.18` ## Impact Attackers with access to this execution surface could infer whether specific files exist (for example secrets/config files), enabling filesystem enumeration and improving follow-on attack planning. ## Fix The safe-bin policy was changed to deterministic argv-only validation without host file-existence checks. File-oriented flags are blocked for safe-bin mode (for example `sort -o`, `jq -f`, `grep -f`), and trusted-path checks remain enforced. ## Fix Commit(s) - `bafdbb6f112409a65decd3d4e7350fbd637c7754` Found using [MCPwner](https://github.com/Pigyon/MCPwner) Thanks @nedlir for reporting.
如何修補 CVE-2026-4040
要修補 CVE-2026-4040,請將受影響套件升級到下列已修補版本。
- —升級至 2026.2.19 或更新版本
CVE-2026-4040 正在被利用嗎?
低 — EPSS 為 0.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2026.2.19
CVSS 分數
| 來源 | 版本 |
|---|