VYPR
High severity8.1NVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026

CVE-2026-53857

CVE-2026-53857

Description

OpenClaw before 2026.5.3 allows Zalo contacts with mutable display names to bypass allowFrom policy, potentially rerouting agent responses.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OpenClaw before 2026.5.3 allows Zalo contacts with mutable display names to bypass allowFrom policy, potentially rerouting agent responses.

Vulnerability

OpenClaw before version 2026.5.3 contains a policy enforcement vulnerability (CWE-290) where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes [1][2]. The feature must be enabled and reachable for the bug to be exploitable. The vulnerability does not change OpenClaw's trusted-operator model; authenticated Gateway operators and installed plugins remain trusted unless crossing a separate security boundary [1].

Exploitation

An attacker needs to be a Zalo contact with the ability to change their display name (mutable display metadata). The attacker changes their display name to match an allowFrom policy entry that is intended for a different Zalo identity [1][2]. The attacker does not require network-level access beyond being a contact; the exploitation relies on the policy binding to mutable display names rather than stable identifiers [2].

Impact

Successful exploitation allows the attacker to receive agent responses that were intended for another Zalo identity [1][2]. The practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path; potential consequences include information disclosure or impersonation of other Zalo contacts [1].

Mitigation

The first stable patched version is 2026.5.3 [1][2]. As workarounds until patching, use stable Zalo identifiers where available, keep friend access restricted, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when not needed [1].

AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • OpenClaw/Openclawinferred2 versions
    <2026.5.3+ 1 more
    • (no CPE)range: <2026.5.3
    • (no CPE)range: <2026.5.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.