PT-2026-49772 · Openclaw · Openclaw

·

CVE-2026-53855

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.2
Description An inline-eval bypass allows authenticated operators to weaken strict allowlist checks using shell positional parameters. By combining allowlisted tools with shell positional arguments, attackers can place inline-eval content in shell carriers that fall outside the intended allowlist rules, enabling the execution of unapproved shell-provided content.
Recommendations Update to version 2026.4.2. Avoid allowlisting shell carrier patterns and require approval for shell wrappers. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the affected feature when it is not needed.

Exploit

Fix

Incomplete List of Disallowed Inputs

Improper Privilege Management

Incorrect Authorization

OS Command Injection

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-53855
GHSA-27PQ-2PH8-8X25
GHSA-5CJ2-3JR2-5H77

Affected Products

Openclaw