PT-2026-49035 · Openclaw · Openclaw

·

CVE-2026-53831

·

Published

2026-06-12

·

Updated

2026-07-02

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.18
Description A policy enforcement issue exists in the system.run safe-bin allowlist validation on POSIX nodes. This flaw allows shell expansion to modify how commands are interpreted. Authenticated operators can use shell metacharacters within approved commands to read unintended node-local files and expose sensitive configuration data.
Recommendations Update to version 2026.5.18.

Exploit

Fix

Time Of Check To Time Of Use

Improper Access Control

Information Disclosure

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53831
GHSA-GWCQ-453V-2FRR
GHSA-MHQ8-78PJ-5J79

Affected Products

Openclaw