Argument Pattern Validation Bypass in OpenClaw by OpenClaw
CVE-2026-53853
7.6HIGH
What is CVE-2026-53853?
OpenClaw versions before 2026.5.12 exhibit a vulnerability that allows an argument pattern validation bypass in the exec allowlist. This flaw enables attackers to execute disallowed arguments when invoking allowlisted executables on both Linux and macOS systems. By circumventing the argPattern restrictions, unauthorized users can potentially gain file or network access, or execute arbitrary commands, posing significant security risks.
Affected Version(s)
OpenClaw 0 < 2026.5.12
OpenClaw 2026.5.12
