CVE 8.7 HIGH

OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution_CVE-2026-53822

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.

AI Analysis

Command injection vulnerability in OpenClaw before 2026.5.18, allowing attackers to execute unapproved commands by modifying command arguments after allowlist approval.

Basic Information

ID CVE-2026-53822
Source VulnCheck
Published Jun 12, 2026 at 21:56

Affected Product

Vendor OpenClaw
Product OpenClaw
Affected Versions OpenClaw OpenClaw 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor OpenClaw
Product OpenClaw
Version < 2026.5.18

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.