High severity8.8NVD Advisory· Published Jun 12, 2026· Updated Jun 16, 2026
CVE-2026-53822
CVE-2026-53822
Description
OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-2j8v-hwgc-x698nvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-command-argument-modification-via-shell-wrapper-between-approval-and-executionnvdThird Party Advisory
News mentions
1- OpenClaw: 25 CVEs Disclosed in Largest Security Batch, Including Code Execution and Critical Auth BypassVypr Intelligence · Jun 12, 2026