PT-2026-49026 · Openclaw · Openclaw

CVE-2026-53822

·

Published

2026-06-12

·

Updated

2026-07-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.18
Description Command injection occurs because the shell wrapper argv can be modified between the approval and execution phases. This allows attackers to rebuild command arguments after they have passed allowlist approval to execute unapproved command shapes, which can bypass security controls.
Recommendations Update to version 2026.5.18.

Exploit

Fix

Time Of Check To Time Of Use

Command Injection

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53822
GHSA-2J8V-HWGC-X698

Affected Products

Openclaw