CVE-2026-53831

OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in approved commands to read unintended node-local files and expose sensitive configuration data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) OpenClaw anterior a 2026.5.18 contiene una vulnerabilidad de aplicación de políticas en la validación de la lista de permitidos (allowlist) de safe-bin de system.run que permite la expansión de shell para modificar la interpretación de comandos en nodos POSIX. Los operadores autenticados pueden explotar metacaracteres de shell en comandos aprobados para leer archivos locales de nodo no deseados y exponer datos de configuración sensibles.

16 Jun 2026, 00:45

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-mhq8-78pj-5j79 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-mhq8-78pj-5j79 - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-arbitrary-file-read-via-shell-expansion-in-system-run-safe-bin-allowlist - () https://www.vulncheck.com/advisories/openclaw-arbitrary-file-read-via-shell-expansion-in-system-run-safe-bin-allowlist - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
CWE NVD-CWE-noinfo
First Time Openclaw
Openclaw openclaw

12 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 22:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-53831

Mitre link : CVE-2026-53831

CVE.ORG link : CVE-2026-53831


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

NVD-CWE-noinfo