CVE-2026-53831: Openclaw
High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in approved commands to read unintended node-local files and expose sensitive configuration data.
Affected products
- Openclaw Openclaw: before 2026.5.18 (fixed in 2026.5.18)
Published 2026-06-12. Last modified 2026-07-23.