Количество 3
Количество 3
CVE-2026-28460
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to execute non-allowlisted commands by splitting command substitution using shell line-continuation characters. Attackers can bypass security analysis by injecting $\\ followed by a newline and opening parenthesis inside double quotes, causing the shell to fold the line continuation into executable command substitution that circumvents approval boundaries.
GHSA-9868-vxmx-w862
OpenClaw's system.run allowlist bypass via shell line-continuation command substitution
BDU:2026-05018
Уязвимость конфигурации tools.exec.security=allowlist ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю выполнить произвольные команды
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-28460 OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to execute non-allowlisted commands by splitting command substitution using shell line-continuation characters. Attackers can bypass security analysis by injecting $\\ followed by a newline and opening parenthesis inside double quotes, causing the shell to fold the line continuation into executable command substitution that circumvents approval boundaries. | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
GHSA-9868-vxmx-w862 OpenClaw's system.run allowlist bypass via shell line-continuation command substitution | 0% Низкий | 5 месяцев назад | ||
BDU:2026-05018 Уязвимость конфигурации tools.exec.security=allowlist ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю выполнить произвольные команды | CVSS3: 8.8 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу