GHSA-3v3j-737j-7g74High· 8.3▾ TwilightDuplicate Advisory: Linux and macOS exec allowlists skipped configured argument patterns
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-v2ww-5rh7-2h5v. This link is maintained to preserve external references.
OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern restrictions by directly invoking allowlisted executables with unrestricted arguments, potentially enabling unauthorized file access, network access, or command execution.
openclaw < 2026.5.12Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53853High· 7.1OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
GHSA-r7vv-6763-m739Low· 4.3Duplicate Advisory: Skill-command dispatch could skip before-tool-call hooks
CVE-2026-53845Low· 4.3OpenClaw: Skill-command dispatch could skip before-tool-call hooks
GHSA-c29c-2q9c-pc86HighOpenClaw: Slack allowFrom could bind to mutable display names
GHSA-qjpc-qf9m-xwmrHigh· 8.8OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
GHSA-gp79-m99v-gjmhMediumOpenClaw: Mattermost handlers could fall open when channel type was missing