OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to execute unapproved commands at runtime.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/commit/b2e8b7d4bb2f22eaa16f5c4b07547774e90b65a5 | Patch |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-x3h8-jrgh-p8jx | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-shell-expansion-bypass-in-unquoted-heredocs-via-exec-allowlist | Third Party Advisory |
Configurations
History
07 May 2026, 17:07
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| First Time |
Openclaw
Openclaw openclaw |
|
| References | () https://github.com/openclaw/openclaw/commit/b2e8b7d4bb2f22eaa16f5c4b07547774e90b65a5 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-x3h8-jrgh-p8jx - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-shell-expansion-bypass-in-unquoted-heredocs-via-exec-allowlist - Third Party Advisory |
06 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-06 20:16
Updated : 2026-05-07 17:07
NVD link : CVE-2026-44115
Mitre link : CVE-2026-44115
CVE.ORG link : CVE-2026-44115
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-184
Incomplete List of Disallowed Inputs
