VYPR
Medium severity6.6NVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026

CVE-2026-53861

CVE-2026-53861

Description

OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. Attackers can execute shell content outside the intended allowlist check by using combined flag forms, potentially allowing unauthorized command execution depending on operator configuration.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
openclawnpm
< 2026.5.62026.5.6

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

1