---
id: CVE-2026-53822
title: >-
  OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between
  Approval and Execution
summary: >-
  OpenClaw before 2026.5.18 contains a command injection vulnerability where
  shell wrapper argv could change between approval and execution. Attackers can
  rebuild command arguments after allowlist approval to execute unapproved
  command sha…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-367
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.5.18
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-15T18:25:53.730170Z'
published: '2026-06-12'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:54:17.424Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-53822'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-2j8v-hwgc-x698
    label: GitHub Security Advisory (GHSA-2j8v-hwgc-x698)
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-command-argument-modification-via-shell-wrapper-between-approval-and-execution
    label: >-
      VulnCheck Advisory: OpenClaw < 2026.5.18 - Command Argument Modification
      via Shell Wrapper Between Approval and Execution
tags:
  - cve.org
epss: 0.01962
epssPercentile: 0.79483
ingestedAt: '2026-09-17T18:25:16.054Z'
---

## Overview

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.

## Affected

- `OpenClaw < 2026.5.18`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
