OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails to recognize. Attackers can craft commands such as piped execution, command substitution, or subshell invocation to bypass the validateScriptFileForShellBleed() validation checks and execute arbitrary script content that would otherwise be blocked.
References
Configurations
History
No history.
Information
Published : 2026-04-02 19:21
Updated : 2026-07-24 21:10
NVD link : CVE-2026-34425
Mitre link : CVE-2026-34425
CVE.ORG link : CVE-2026-34425
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-184
Incomplete List of Disallowed Inputs
