High severity8.0NVD Advisory· Published Jun 12, 2026· Updated Jun 16, 2026
CVE-2026-53829
CVE-2026-53829
Description
OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-xww8-gqvh-92x9nvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-command-truncation-in-exec-approval-displaynvdThird Party Advisory
News mentions
1- OpenClaw: 25 CVEs Disclosed in Largest Security Batch, Including Code Execution and Critical Auth BypassVypr Intelligence · Jun 12, 2026