PT-2026-49033 · Openclaw · Openclaw

·

CVE-2026-53829

·

Published

2026-06-12

·

Updated

2026-07-02

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.18
Description An approval display truncation issue allows authenticated users to hide command suffixes from approvers. This enables attackers to submit oversized exec commands that feature benign prefixes and malicious suffixes, leading to the execution of unauthorized operations once the command is approved.
Recommendations Update to version 2026.5.18.

Exploit

Fix

UI Misrepresentation of Critical Information

Improper Access Control

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53829
GHSA-XWW8-GQVH-92X9

Affected Products

Openclaw