{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-28363",
        "tracking": {
            "current_release_date": "2026-04-02T08:16:33.612385Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-28363",
            "initial_release_date": "2026-02-27T04:25:31.896040Z",
            "revision_history": [
                {
                    "date": "2026-02-27T04:25:31.896040Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-02-27T04:25:35.795069Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-27T04:38:42.546787Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-02-27T04:38:43.701551Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-27T11:05:44.702004Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Products created (1).| References created (11)."
                },
                {
                    "date": "2026-02-27T11:05:51.817719Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-27T14:36:56.867338Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-02-27T14:37:09.081058Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-27T16:38:58.730279Z",
                    "number": "9",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-02-27T19:26:51.427503Z",
                    "number": "10",
                    "summary": "Products created (1).| Product Identifiers created (1)."
                },
                {
                    "date": "2026-02-27T19:26:53.367164Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-27T21:29:40.202981Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T02:39:43.461035Z",
                    "number": "13",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-02-28T02:39:48.674888Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T06:55:46.988886Z",
                    "number": "15",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-01T11:23:12.220796Z",
                    "number": "16",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (53).| Products created (7).| References created (1)."
                },
                {
                    "date": "2026-03-01T11:23:21.353678Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T18:21:32.854807Z",
                    "number": "18",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-04T18:21:38.709557Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:37:42.181945Z",
                    "number": "20",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:37:44.696028Z",
                    "number": "21",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-29T18:48:18.198478Z",
                    "number": "22",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (6).| CWES updated (1)."
                },
                {
                    "date": "2026-03-29T18:48:25.123596Z",
                    "number": "23",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-02T08:12:58.903463Z",
                    "number": "24",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "24"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<2026.2.26",
                                "product": {
                                    "name": "vers:unknown/<2026.2.26",
                                    "product_id": "CSAFPID-5734985"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenClaw"
                    }
                ],
                "category": "vendor",
                "name": "Open Source"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<2026.2.23",
                                "product": {
                                    "name": "vers:unknown/<2026.2.23",
                                    "product_id": "CSAFPID-5734223"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenClaw"
                    }
                ],
                "category": "vendor",
                "name": "OpenClaw"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2026.2.23",
                                "product": {
                                    "name": "vers:unknown/2026.2.23",
                                    "product_id": "CSAFPID-5961934"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<2026.2.23",
                                "product": {
                                    "name": "vers:unknown/<2026.2.23",
                                    "product_id": "CSAFPID-5961935"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "npm/openclaw"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<2026.2.23",
                                "product": {
                                    "name": "vers:unknown/<2026.2.23",
                                    "product_id": "CSAFPID-5736287",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<2026.2.23",
                                "product": {
                                    "name": "vers:unknown/>=0|<2026.2.23",
                                    "product_id": "CSAFPID-5737701"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.0",
                                "product": {
                                    "name": "vers:unknown/v0.1.0",
                                    "product_id": "CSAFPID-5502989"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.1",
                                "product": {
                                    "name": "vers:unknown/v0.1.1",
                                    "product_id": "CSAFPID-5502990"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.2",
                                "product": {
                                    "name": "vers:unknown/v0.1.2",
                                    "product_id": "CSAFPID-5502991"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.3",
                                "product": {
                                    "name": "vers:unknown/v0.1.3",
                                    "product_id": "CSAFPID-5502992"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.4",
                                "product": {
                                    "name": "vers:unknown/v1.0.4",
                                    "product_id": "CSAFPID-5502993"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.0",
                                "product": {
                                    "name": "vers:unknown/v1.1.0",
                                    "product_id": "CSAFPID-5502994"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.0",
                                "product": {
                                    "name": "vers:unknown/v1.2.0",
                                    "product_id": "CSAFPID-5502995"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.1",
                                "product": {
                                    "name": "vers:unknown/v1.2.1",
                                    "product_id": "CSAFPID-5502996"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.2",
                                "product": {
                                    "name": "vers:unknown/v1.2.2",
                                    "product_id": "CSAFPID-5502997"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.3.0",
                                "product": {
                                    "name": "vers:unknown/v1.3.0",
                                    "product_id": "CSAFPID-5502998"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0-beta1",
                                "product": {
                                    "name": "vers:unknown/v2.0.0-beta1",
                                    "product_id": "CSAFPID-5502999"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0-beta2",
                                "product": {
                                    "name": "vers:unknown/v2.0.0-beta2",
                                    "product_id": "CSAFPID-5503000"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0-beta3",
                                "product": {
                                    "name": "vers:unknown/v2.0.0-beta3",
                                    "product_id": "CSAFPID-5503001"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0-beta4",
                                "product": {
                                    "name": "vers:unknown/v2.0.0-beta4",
                                    "product_id": "CSAFPID-5503002"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0-beta5",
                                "product": {
                                    "name": "vers:unknown/v2.0.0-beta5",
                                    "product_id": "CSAFPID-5503003"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.10",
                                "product": {
                                    "name": "vers:unknown/v2026.1.10",
                                    "product_id": "CSAFPID-5503004"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.11",
                                "product": {
                                    "name": "vers:unknown/v2026.1.11",
                                    "product_id": "CSAFPID-5503005"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.11-1",
                                "product": {
                                    "name": "vers:unknown/v2026.1.11-1",
                                    "product_id": "CSAFPID-5503006"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.11-2",
                                "product": {
                                    "name": "vers:unknown/v2026.1.11-2",
                                    "product_id": "CSAFPID-5503007"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.11-3",
                                "product": {
                                    "name": "vers:unknown/v2026.1.11-3",
                                    "product_id": "CSAFPID-5503008"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.12",
                                "product": {
                                    "name": "vers:unknown/v2026.1.12",
                                    "product_id": "CSAFPID-5503009"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.12-2",
                                "product": {
                                    "name": "vers:unknown/v2026.1.12-2",
                                    "product_id": "CSAFPID-5503010"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.13",
                                "product": {
                                    "name": "vers:unknown/v2026.1.13",
                                    "product_id": "CSAFPID-5503011"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.14-1",
                                "product": {
                                    "name": "vers:unknown/v2026.1.14-1",
                                    "product_id": "CSAFPID-5503012"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.15",
                                "product": {
                                    "name": "vers:unknown/v2026.1.15",
                                    "product_id": "CSAFPID-5503013"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.16-2",
                                "product": {
                                    "name": "vers:unknown/v2026.1.16-2",
                                    "product_id": "CSAFPID-5503014"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.20",
                                "product": {
                                    "name": "vers:unknown/v2026.1.20",
                                    "product_id": "CSAFPID-5503015"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.21",
                                "product": {
                                    "name": "vers:unknown/v2026.1.21",
                                    "product_id": "CSAFPID-5503016"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.22",
                                "product": {
                                    "name": "vers:unknown/v2026.1.22",
                                    "product_id": "CSAFPID-5503017"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.23",
                                "product": {
                                    "name": "vers:unknown/v2026.1.23",
                                    "product_id": "CSAFPID-5503018"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.24",
                                "product": {
                                    "name": "vers:unknown/v2026.1.24",
                                    "product_id": "CSAFPID-5503019"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.24-1",
                                "product": {
                                    "name": "vers:unknown/v2026.1.24-1",
                                    "product_id": "CSAFPID-5503020"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.29",
                                "product": {
                                    "name": "vers:unknown/v2026.1.29",
                                    "product_id": "CSAFPID-5559506"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.30",
                                "product": {
                                    "name": "vers:unknown/v2026.1.30",
                                    "product_id": "CSAFPID-5661660"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.5",
                                "product": {
                                    "name": "vers:unknown/v2026.1.5",
                                    "product_id": "CSAFPID-5503021"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.5-1",
                                "product": {
                                    "name": "vers:unknown/v2026.1.5-1",
                                    "product_id": "CSAFPID-5503022"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.5-2",
                                "product": {
                                    "name": "vers:unknown/v2026.1.5-2",
                                    "product_id": "CSAFPID-5503023"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.5-3",
                                "product": {
                                    "name": "vers:unknown/v2026.1.5-3",
                                    "product_id": "CSAFPID-5503024"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.8",
                                "product": {
                                    "name": "vers:unknown/v2026.1.8",
                                    "product_id": "CSAFPID-5503025"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.1.9",
                                "product": {
                                    "name": "vers:unknown/v2026.1.9",
                                    "product_id": "CSAFPID-5503026"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.1",
                                "product": {
                                    "name": "vers:unknown/v2026.2.1",
                                    "product_id": "CSAFPID-5661661"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.12",
                                "product": {
                                    "name": "vers:unknown/v2026.2.12",
                                    "product_id": "CSAFPID-5661662"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.13",
                                "product": {
                                    "name": "vers:unknown/v2026.2.13",
                                    "product_id": "CSAFPID-5661663"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.14",
                                "product": {
                                    "name": "vers:unknown/v2026.2.14",
                                    "product_id": "CSAFPID-5661671"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.15-beta.1",
                                "product": {
                                    "name": "vers:unknown/v2026.2.15-beta.1",
                                    "product_id": "CSAFPID-5661672"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.17",
                                "product": {
                                    "name": "vers:unknown/v2026.2.17",
                                    "product_id": "CSAFPID-5661673"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.19",
                                "product": {
                                    "name": "vers:unknown/v2026.2.19",
                                    "product_id": "CSAFPID-5752204"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.19-beta.1",
                                "product": {
                                    "name": "vers:unknown/v2026.2.19-beta.1",
                                    "product_id": "CSAFPID-5752205"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.2",
                                "product": {
                                    "name": "vers:unknown/v2026.2.2",
                                    "product_id": "CSAFPID-5661664"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.21",
                                "product": {
                                    "name": "vers:unknown/v2026.2.21",
                                    "product_id": "CSAFPID-5752206"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.21-beta.1",
                                "product": {
                                    "name": "vers:unknown/v2026.2.21-beta.1",
                                    "product_id": "CSAFPID-5752207"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.22",
                                "product": {
                                    "name": "vers:unknown/v2026.2.22",
                                    "product_id": "CSAFPID-5752208"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.22-beta.1",
                                "product": {
                                    "name": "vers:unknown/v2026.2.22-beta.1",
                                    "product_id": "CSAFPID-5752209"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.23-beta.1",
                                "product": {
                                    "name": "vers:unknown/v2026.2.23-beta.1",
                                    "product_id": "CSAFPID-5752210"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.3",
                                "product": {
                                    "name": "vers:unknown/v2026.2.3",
                                    "product_id": "CSAFPID-5661665"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.6",
                                "product": {
                                    "name": "vers:unknown/v2026.2.6",
                                    "product_id": "CSAFPID-5661666"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.6-1",
                                "product": {
                                    "name": "vers:unknown/v2026.2.6-1",
                                    "product_id": "CSAFPID-5661667"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.6-2",
                                "product": {
                                    "name": "vers:unknown/v2026.2.6-2",
                                    "product_id": "CSAFPID-5661668"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.6-3",
                                "product": {
                                    "name": "vers:unknown/v2026.2.6-3",
                                    "product_id": "CSAFPID-5661669"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2026.2.9",
                                "product": {
                                    "name": "vers:unknown/v2026.2.9",
                                    "product_id": "CSAFPID-5661670"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "openclaw"
                    }
                ],
                "category": "vendor",
                "name": "openclaw"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-28363",
            "cwe": {
                "id": "CWE-184",
                "name": "Incomplete List of Disallowed Inputs"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was denied.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-28363"
                },
                {
                    "category": "description",
                    "text": "In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was denied.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-28363"
                },
                {
                    "category": "description",
                    "text": "In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was denied.",
                    "title": "github - https://github.com/advisories/GHSA-7977-c43c-xpwj"
                },
                {
                    "category": "description",
                    "text": "In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was denied.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-7977-c43c-xpwj.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was denied.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-28363.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "### Summary\nIn OpenClaw, `tools.exec.safeBins` validation for `sort` could be bypassed via GNU long-option abbreviations in allowlist mode, allowing approval-free execution paths that should require approval.\n\n### Affected Packages / Versions\n- Ecosystem: npm\n- Package: `openclaw`\n- Latest published version checked: `2026.2.22-2`\n- Affected range: `<= 2026.2.22-2`\n- Fixed version: `2026.2.23`\n\n### Impact\nWhen all of the following are true:\n- `tools.exec.security=allowlist`\n- `tools.exec.ask=on-miss`\n- `tools.exec.safeBins` includes `sort`\n\nabbreviated GNU long options (for example `--compress-prog`) could bypass denied-flag checks and be treated as allowlist-satisfied safe-bin usage, skipping approval.\n\n### Root Cause\nLong-option handling matched denied flags by exact string and accepted unknown long options with inline values instead of failing closed.\n\n### Fix Commit(s)\n- `3b8e33037ae2e12af7beb56fcf0346f1f8cbde6f`\n\n### Release Process Note\n`patched_versions` is pre-set to the released version (`2026.2.23`). This advisory now reflects released fix version `2026.2.23`.\n\nOpenClaw thanks @tdjackey for reporting.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-3c6h-g97w-fg78.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was denied.",
                    "title": "gitlab - https://gitlab.com/api/v4/projects/25847700/repository/files/npm%2Fopenclaw%2FCVE-2026-28363.yml/raw"
                },
                {
                    "category": "other",
                    "text": "0.00099",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.9",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent CVSS (V3) score, There is product data available from source Certbundde",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "There is cwe data available from source Github",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-5961934"
                ],
                "known_affected": [
                    "CSAFPID-5734223",
                    "CSAFPID-5734985",
                    "CSAFPID-5736287",
                    "CSAFPID-5737701",
                    "CSAFPID-5502989",
                    "CSAFPID-5502990",
                    "CSAFPID-5502991",
                    "CSAFPID-5502992",
                    "CSAFPID-5502993",
                    "CSAFPID-5502994",
                    "CSAFPID-5502995",
                    "CSAFPID-5502996",
                    "CSAFPID-5502997",
                    "CSAFPID-5502998",
                    "CSAFPID-5502999",
                    "CSAFPID-5503000",
                    "CSAFPID-5503001",
                    "CSAFPID-5503002",
                    "CSAFPID-5503003",
                    "CSAFPID-5503004",
                    "CSAFPID-5503005",
                    "CSAFPID-5503006",
                    "CSAFPID-5503007",
                    "CSAFPID-5503008",
                    "CSAFPID-5503009",
                    "CSAFPID-5503010",
                    "CSAFPID-5503011",
                    "CSAFPID-5503012",
                    "CSAFPID-5503013",
                    "CSAFPID-5503014",
                    "CSAFPID-5503015",
                    "CSAFPID-5503016",
                    "CSAFPID-5503017",
                    "CSAFPID-5503018",
                    "CSAFPID-5503019",
                    "CSAFPID-5503020",
                    "CSAFPID-5503021",
                    "CSAFPID-5503022",
                    "CSAFPID-5503023",
                    "CSAFPID-5503024",
                    "CSAFPID-5503025",
                    "CSAFPID-5503026",
                    "CSAFPID-5559506",
                    "CSAFPID-5661660",
                    "CSAFPID-5661661",
                    "CSAFPID-5661662",
                    "CSAFPID-5661663",
                    "CSAFPID-5661664",
                    "CSAFPID-5661665",
                    "CSAFPID-5661666",
                    "CSAFPID-5661667",
                    "CSAFPID-5661668",
                    "CSAFPID-5661669",
                    "CSAFPID-5661670",
                    "CSAFPID-5661671",
                    "CSAFPID-5661672",
                    "CSAFPID-5661673",
                    "CSAFPID-5752204",
                    "CSAFPID-5752205",
                    "CSAFPID-5752206",
                    "CSAFPID-5752207",
                    "CSAFPID-5752208",
                    "CSAFPID-5752209",
                    "CSAFPID-5752210",
                    "CSAFPID-5961935"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28363"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-28363"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-28363"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/28xxx/CVE-2026-28363.json"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0551.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-28363"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-7977-c43c-xpwj"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-7977-c43c-xpwj"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-7977-c43c-xpwj.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-28363.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-3c6h-g97w-fg78.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - gitlab",
                    "url": "https://gitlab.com/api/v4/projects/25847700/repository/files/npm%2Fopenclaw%2FCVE-2026-28363.yml/raw"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv",
                    "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-3c6h-g97w-fg78"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0551.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0551"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/advisories/GHSA-7977-C43C-XPWJ"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-7qf6-h84j-8fq4"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-f7ww-2725-qvw2"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-hjvp-qhm6-wrh2"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-mwxv-35wr-4vvj"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-qcc4-p59m-p54m"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-r65x-2hqr-j5hf"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-v8cg-4474-49v8"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-vjp8-wprm-2jw9"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28363"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab; osv",
                    "url": "https://github.com/openclaw/openclaw/commit/3b8e33037ae2e12af7beb56fcf0346f1f8cbde6f"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab; osv",
                    "url": "https://github.com/openclaw/openclaw/releases/tag/v2026.2.23"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab",
                    "url": "https://github.com/advisories/GHSA-7977-c43c-xpwj"
                },
                {
                    "category": "external",
                    "summary": "Reference - gitlab",
                    "url": "https://github.com/openclaw/openclaw"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-5502989",
                        "CSAFPID-5502990",
                        "CSAFPID-5502991",
                        "CSAFPID-5502992",
                        "CSAFPID-5502993",
                        "CSAFPID-5502994",
                        "CSAFPID-5502995",
                        "CSAFPID-5502996",
                        "CSAFPID-5502997",
                        "CSAFPID-5502998",
                        "CSAFPID-5502999",
                        "CSAFPID-5503000",
                        "CSAFPID-5503001",
                        "CSAFPID-5503002",
                        "CSAFPID-5503003",
                        "CSAFPID-5503004",
                        "CSAFPID-5503005",
                        "CSAFPID-5503006",
                        "CSAFPID-5503007",
                        "CSAFPID-5503008",
                        "CSAFPID-5503009",
                        "CSAFPID-5503010",
                        "CSAFPID-5503011",
                        "CSAFPID-5503012",
                        "CSAFPID-5503013",
                        "CSAFPID-5503014",
                        "CSAFPID-5503015",
                        "CSAFPID-5503016",
                        "CSAFPID-5503017",
                        "CSAFPID-5503018",
                        "CSAFPID-5503019",
                        "CSAFPID-5503020",
                        "CSAFPID-5503021",
                        "CSAFPID-5503022",
                        "CSAFPID-5503023",
                        "CSAFPID-5503024",
                        "CSAFPID-5503025",
                        "CSAFPID-5503026",
                        "CSAFPID-5559506",
                        "CSAFPID-5661660",
                        "CSAFPID-5661661",
                        "CSAFPID-5661662",
                        "CSAFPID-5661663",
                        "CSAFPID-5661664",
                        "CSAFPID-5661665",
                        "CSAFPID-5661666",
                        "CSAFPID-5661667",
                        "CSAFPID-5661668",
                        "CSAFPID-5661669",
                        "CSAFPID-5661670",
                        "CSAFPID-5661671",
                        "CSAFPID-5661672",
                        "CSAFPID-5661673",
                        "CSAFPID-5734223",
                        "CSAFPID-5734985",
                        "CSAFPID-5736287",
                        "CSAFPID-5737701",
                        "CSAFPID-5752204",
                        "CSAFPID-5752205",
                        "CSAFPID-5752206",
                        "CSAFPID-5752207",
                        "CSAFPID-5752208",
                        "CSAFPID-5752209",
                        "CSAFPID-5752210",
                        "CSAFPID-5961935"
                    ]
                }
            ],
            "title": "CVE-2026-28363"
        }
    ]
}