8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to execute unapproved commands at runtime.
AI Analysis
Shell expansion bypass vulnerability in unquoted heredoc bodies via exec allowlist
Basic Information
ID
CVE-2026-44115
Source
VulnCheck
Published
May 6, 2026 at 19:49
Affected Product
Vendor
OpenClaw
Product
OpenClaw
Affected Versions
OpenClaw OpenClaw 0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
OpenClaw
Product
OpenClaw
Version
< 2026.4.22