OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by using combined shell options to execute inline shell content without intended allowlist validation, potentially enabling unauthorized command execution when the affected feature is enabled.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-vxx3-6hc9-7cc3 | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-shell-option-parsing-bypass-in-exec-revalidation | Third Party Advisory |
Configurations
History
12 Jun 2026, 19:33
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openclaw
Openclaw openclaw |
|
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-vxx3-6hc9-7cc3 - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-shell-option-parsing-bypass-in-exec-revalidation - Third Party Advisory | |
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
11 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-11 21:16
Updated : 2026-06-12 19:33
NVD link : CVE-2026-53806
Mitre link : CVE-2026-53806
CVE.ORG link : CVE-2026-53806
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
