#VU125265 Incomplete List of Disallowed Inputs in OpenClaw - CVE-2026-34425
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to bypass script-content preflight validation.
The vulnerability exists due to incomplete list of disallowed inputs in exec script preflight validation when processing complex interpreter invocations such as pipes or other non-simple command forms. A remote attacker can supply an attacker-controlled command shape to bypass script-content preflight validation.
This issue weakens a defense-in-depth guard that was intended to block unsafe script content before execution.