PT-2026-49024 · Openclaw · Openclaw

·

CVE-2026-53820

·

Published

2026-06-12

·

Updated

2026-07-02

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.12
Description An exec denylist bypass exists in the bundle MCP loopback session-spawn path. This allows authenticated callers to bypass intended command restrictions and start sessions with broader command reach than intended.
Recommendations Update to version 2026.5.12.

Exploit

Fix

Missing Authorization

Improper Access Control

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53820
GHSA-QH2F-99MV-MRCF

Affected Products

Openclaw