OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-xww8-gqvh-92x9 | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-command-truncation-in-exec-approval-display | Third Party Advisory |
Configurations
History
16 Jun 2026, 02:55
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-xww8-gqvh-92x9 - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-command-truncation-in-exec-approval-display - Third Party Advisory | |
| First Time |
Openclaw
Openclaw openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
12 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-12 22:16
Updated : 2026-06-16 02:55
NVD link : CVE-2026-53829
Mitre link : CVE-2026-53829
CVE.ORG link : CVE-2026-53829
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-451
User Interface (UI) Misrepresentation of Critical Information
