CVE-2026-53814High· 8.4▾ TwilightOpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
OpenClaw hook ingress can start automated agent runs using a configured hook token. In affected releases, a hook-triggered run could select a bundled CLI backend that received owner-scoped MCP loopback authority instead of a scope appropriate for hook ingress.
This issue affects the boundary between hook-token automation and owner-only MCP tools. It does not affect deployments with hooks disabled.
This affects deployments where hooks are enabled, /hooks/agent is reachable with a valid hook token, and a bundled CLI backend can be selected for the hook-triggered run.
A caller with the hook token could cause the spawned CLI runtime to see or call MCP tools that should have been owner-only. The practical impact depends on which MCP tools are available; the reported proof used persistent cron state as a representative owner-only action.
The first stable patched version is 2026.5.20.
Fixed in the 2026.5.20 stable release.
Upgrade to [email protected] or later. Keep hook tokens secret, restrict network access to hook endpoints, and disable hooks when they are not needed.
openclaw < 2026.5.20Upgrade to a patched release:
openclaw 2026.5.20Connected by shared product, vendor, weakness, or advisory.
GHSA-mhq8-78pj-5j79High· 7.1OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
CVE-2026-53815High· 6.5OpenClaw: Message read actions could skip channel allowlist checks
GHSA-xww8-gqvh-92x9High· 8.0OpenClaw: Exec approval display truncation could hide the command being approved
GHSA-qh2f-99mv-mrcfMediumOpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
GHSA-2j8v-hwgc-x698HighOpenClaw: Shell wrapper argv could change between approval and execution