PT-2026-49778 · Openclaw · Openclaw

·

CVE-2026-53861

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.6
Description The macOS Swift exec feature contains an allowlist bypass. The issue occurs because the system fails to account for combined POSIX inline-command flags, which are shorthand ways of grouping multiple command-line options together. This allows attackers to execute shell content that bypasses the intended allowlist checks, potentially leading to unauthorized command execution depending on the operator configuration.
Recommendations Update to version 2026.5.6. Require approval for combined shell flag forms on macOS. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the macOS Swift exec feature when it is not needed.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53861
GHSA-C226-Q6FX-6J6C
GHSA-G796-JQMX-WF9Q

Affected Products

Openclaw