Argument Pattern Validation Bypass in OpenClaw by OpenClaw
CVE-2026-53853

7.6HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-53853?

OpenClaw versions before 2026.5.12 exhibit a vulnerability that allows an argument pattern validation bypass in the exec allowlist. This flaw enables attackers to execute disallowed arguments when invoking allowlisted executables on both Linux and macOS systems. By circumventing the argPattern restrictions, unauthorized users can potentially gain file or network access, or execute arbitrary commands, posing significant security risks.

Affected Version(s)

OpenClaw 0 < 2026.5.12

OpenClaw 2026.5.12

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Curly-Haired-Baboon
.