CVE-2026-15193

A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. The affected element is an unknown function of the file android/app/src/main/java/com/openclaw/android/JsBridge.kt of the component Android WebView Bridge. This manipulation causes os command injection. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
Configurations

No configuration.

History

09 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-09 17:16

Updated : 2026-07-09 19:03


NVD link : CVE-2026-15193

Mitre link : CVE-2026-15193

CVE.ORG link : CVE-2026-15193


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')