OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails to recognize. Attackers can craft commands such as piped execution, command substitution, or subshell invocation to bypass the validateScriptFileForShellBleed() validation checks and execute arbitrary script content that would otherwise be blocked.
References
Configurations
History
15 Apr 2026, 17:40
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openclaw openclaw
Openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/openclaw/openclaw/commit/8aceaf5d0f0ec552b75a792f7f0a3bfa5b091513 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-fvx6-pj3r-5q4q - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-shell-bleed-protection-preflight-validation-bypass - Third Party Advisory |
02 Apr 2026, 19:21
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-02 19:21
Updated : 2026-04-15 17:40
NVD link : CVE-2026-34425
Mitre link : CVE-2026-34425
CVE.ORG link : CVE-2026-34425
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-184
Incomplete List of Disallowed Inputs
