VYPR
Low severity3.8NVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026

CVE-2026-53809

CVE-2026-53809

Description

OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusion to select bundled tool access outside intended provider policy restrictions when the affected feature is enabled.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • OpenClaw/Openclawinferred3 versions
    <2026.4.25+ 2 more
    • (no CPE)range: <2026.4.25
    • cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*range: <2026.4.25
    • (no CPE)range: <2026.4.25

Patches

Vulnerability mechanics

References

2

News mentions

1