CVE-2026-22169 | OpenClaw up to 2026.2.21 tools.exec.safeBins sort os command injection (GHSA-vmqr-rc7x-3446)
A vulnerability identified as critical has been detected in OpenClaw up to 2026.2.21. This issue affects the function tools.exec.safeBins. Performing a manipulation of the argument sort results in os command injection.
This vulnerability is known as CVE-2026-22169. Attacking locally is a requirement. No exploit is available.
You should upgrade the affected component.