High severity8.8NVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026
CVE-2026-53806
CVE-2026-53806
Description
OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by using combined shell options to execute inline shell content without intended allowlist validation, potentially enabling unauthorized command execution when the affected feature is enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-vxx3-6hc9-7cc3nvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-shell-option-parsing-bypass-in-exec-revalidationnvdThird Party Advisory
News mentions
1- OpenClaw: 14 Vulnerabilities Disclosed in Single Batch, Including Code Execution and Privilege EscalationVypr Intelligence · Jun 11, 2026