GHSA-wrr6-p5r6-474mLow· 4.3▾ SunlitDuplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-cwpp-5962-q4f6. This link is maintained to preserve external references.
OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wrapper-level side effects outside allowlisted command intent. Attackers can craft command requests that bypass allowlist validation by leveraging transparent command wrappers to perform unintended operations.
openclaw <= 2026.5.22Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53848Low· 4.3OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
GHSA-j472-gf56-x589HighOpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
GHSA-27pq-2ph8-8x25High· 8.1Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks
GHSA-g796-jqmx-wf9qMedium· 6.6Duplicate Advisory: macOS Swift exec allowlist missed combined POSIX inline flags
GHSA-vr6h-vxqj-3pjxHigh· 8.1Duplicate Advisory: Host environment sanitizer missed two Node.js control variables
CVE-2026-53864High· 8.1OpenClaw: Host environment sanitizer missed two Node.js control variables