Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v2r-mv47-wxfr

Опубликовано: 13 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.

EPSS

Процентиль: 59%
0.00982
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-367
CWE-77

Связанные уязвимости

CVSS3: 8.8
nvd
2 месяца назад

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.

EPSS

Процентиль: 59%
0.00982
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-367
CWE-77