GHSA-g796-jqmx-wf9qMedium· 6.6▾ SunlitDuplicate Advisory: macOS Swift exec allowlist missed combined POSIX inline flags
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-c226-q6fx-6j6c. This link is maintained to preserve external references.
OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. Attackers can execute shell content outside the intended allowlist check by using combined flag forms, potentially allowing unauthorized command execution depending on operator configuration.
openclaw <= 2026.5.5Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53861Medium· 6.6OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
GHSA-j472-gf56-x589HighOpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
GHSA-wrr6-p5r6-474mLow· 4.3Duplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers
GHSA-27pq-2ph8-8x25High· 8.1Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks
GHSA-vr6h-vxqj-3pjxHigh· 8.1Duplicate Advisory: Host environment sanitizer missed two Node.js control variables
CVE-2026-53864High· 8.1OpenClaw: Host environment sanitizer missed two Node.js control variables