Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53822

Опубликовано: 12 июн. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Версия до 2026.5.18 (исключая)

EPSS

Процентиль: 62%
0.01076
Низкий

8.8 High

CVSS3

Дефекты

CWE-367
CWE-77

Связанные уязвимости

CVSS3: 8.8
github
2 месяца назад

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.

EPSS

Процентиль: 62%
0.01076
Низкий

8.8 High

CVSS3

Дефекты

CWE-367
CWE-77