Back to overview

CVE-2026-53822

HIGH
8.8
CVSS 3.1
Description
OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.

Metadata

CVE ID
CVE-2026-53822
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-10 21:16 UTC
Published
2026-06-12 21:56 UTC
Last updated
2026-06-12 21:56 UTC
Primary CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
Vendor / Product
OpenClaw / OpenClaw
Sources
cve.org  ·  NVD

Severity & Metrics

8.8 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
OpenClaw OpenClaw 0 < 2026.5.18, 2026.5.18
Weakness (CWE)
CWESourceDescription
CWE-367 cna Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.8 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References (2)
Back to overview