GHSA-27pq-2ph8-8x25High· 8.1▾ TwilightDuplicate Advisory: Shell positional parameters could weaken strict inline-eval checks
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-5cj2-3jr2-5h77. This link is maintained to preserve external references.
OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools with shell positional arguments to place inline-eval content in shell carriers outside intended allowlist rules, enabling execution of unapproved shell-provided content.
openclaw < 2026.4.2Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53855High· 8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks
GHSA-j472-gf56-x589HighOpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
GHSA-wrr6-p5r6-474mLow· 4.3Duplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers
GHSA-g796-jqmx-wf9qMedium· 6.6Duplicate Advisory: macOS Swift exec allowlist missed combined POSIX inline flags
GHSA-vr6h-vxqj-3pjxHigh· 8.1Duplicate Advisory: Host environment sanitizer missed two Node.js control variables
CVE-2026-53864High· 8.1OpenClaw: Host environment sanitizer missed two Node.js control variables