OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusion to select bundled tool access outside intended provider policy restrictions when the affected feature is enabled.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-p39j-x9h5-q66m | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-provider-alias-confusion-in-embedded-runner-policy | Third Party Advisory |
Configurations
History
12 Jun 2026, 19:32
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-p39j-x9h5-q66m - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-provider-alias-confusion-in-embedded-runner-policy - Third Party Advisory | |
| First Time |
Openclaw
Openclaw openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
11 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-11 21:16
Updated : 2026-06-12 19:32
NVD link : CVE-2026-53809
Mitre link : CVE-2026-53809
CVE.ORG link : CVE-2026-53809
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-863
Incorrect Authorization
