PT-2026-49026 · Openclaw · Openclaw
CVE-2026-53822
·
Published
2026-06-12
·
Updated
2026-07-02
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.5.18
Description
Command injection occurs because the shell wrapper
argv can be modified between the approval and execution phases. This allows attackers to rebuild command arguments after they have passed allowlist approval to execute unapproved command shapes, which can bypass security controls.Recommendations
Update to version 2026.5.18.
Exploit
Fix
Time Of Check To Time Of Use
Command Injection
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw