CVE-2026-53861

Published
View on NVD ↗
CVSS v3
6.6
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. Attackers can execute shell content outside the intended allowlist check by using combined flag forms, potentially allowing unauthorized command execution depending on operator configuration.

Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞
GitHubGitHub
380K