OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to execute unapproved commands at runtime.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/commit/b2e8b7d4bb2f22eaa16f5c4b07547774e90b65a5 | Patch |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-x3h8-jrgh-p8jx | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-shell-expansion-bypass-in-unquoted-heredocs-via-exec-allowlist | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-05-06 20:16
Updated : 2026-06-17 10:50
NVD link : CVE-2026-44115
Mitre link : CVE-2026-44115
CVE.ORG link : CVE-2026-44115
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-184
Incomplete List of Disallowed Inputs
