Hook Bypass Vulnerability in OpenClaw Product by OpenClaw Vendor
CVE-2026-53845

2.3LOW

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-53845?

OpenClaw versions prior to 2026.5.6 are susceptible to a hook bypass vulnerability that allows attackers to execute skill commands through a potentially vulnerable dispatch path. This exploit circumvents essential hook-based auditing and policy enforcement processes designed to maintain security and integrity. By leveraging this weakness, malicious actors can bypass critical oversight, potentially leading to unauthorized actions within the system.

Affected Version(s)

OpenClaw 0 < 2026.5.6

OpenClaw 2026.5.6

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zsx (@zsxsoft)
qclawer
KeenSecurityLab
.