Описание
OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.
Ссылки
- MitigationVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2026.5.18 (исключая)
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 62%
0.01076
Низкий
8.8 High
CVSS3
Дефекты
CWE-367
CWE-77
Связанные уязвимости
CVSS3: 8.8
github
2 месяца назад
OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.
EPSS
Процентиль: 62%
0.01076
Низкий
8.8 High
CVSS3
Дефекты
CWE-367
CWE-77