PT-2026-49770 · Openclaw · Openclaw

·

CVE-2026-53853

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.12
Description An argument pattern validation bypass exists in the exec allowlist on Linux and macOS systems. When tools.exec.security is set to allowlist, the system skips argPattern checks and treats a matching executable path as sufficient for approval. This allows attackers to bypass configured argPattern restrictions by invoking allowlisted executables with unrestricted arguments, potentially leading to unauthorized file access, network access, or command execution. This issue specifically affects deployments where at least one allowlist entry uses argPattern and the executable accepts security-relevant flags, such as git, python, node, bash, find, tar, and ssh.
Recommendations Update to version 2026.5.12 or later. Review allowlist entries that combine an executable path with argPattern, particularly for interpreter-like or subprocess-capable tools.

Exploit

Fix

Protection Mechanism Failure

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53853
GHSA-3V3J-737J-7G74
GHSA-V2WW-5RH7-2H5V

Affected Products

Openclaw