GHSA-v383-2wgg-v483HighCVSS 8.1

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command...

Published
June 16, 2026
Last Modified
June 16, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser case missing the expected allowlist decision, enabling shell content execution without intended approval prompts.

🔗 References (4)