CVE-2026-34425

OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails to recognize. Attackers can craft commands such as piped execution, command substitution, or subshell invocation to bypass the validateScriptFileForShellBleed() validation checks and execute arbitrary script content that would otherwise be blocked.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

15 Apr 2026, 17:40

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/commit/8aceaf5d0f0ec552b75a792f7f0a3bfa5b091513 - () https://github.com/openclaw/openclaw/commit/8aceaf5d0f0ec552b75a792f7f0a3bfa5b091513 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-fvx6-pj3r-5q4q - () https://github.com/openclaw/openclaw/security/advisories/GHSA-fvx6-pj3r-5q4q - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-shell-bleed-protection-preflight-validation-bypass - () https://www.vulncheck.com/advisories/openclaw-shell-bleed-protection-preflight-validation-bypass - Third Party Advisory

02 Apr 2026, 19:21

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 19:21

Updated : 2026-04-15 17:40


NVD link : CVE-2026-34425

Mitre link : CVE-2026-34425

CVE.ORG link : CVE-2026-34425


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-184

Incomplete List of Disallowed Inputs