Input validation error in OpenClaw - #VU127179
Published: April 23, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass exec allowlist analysis.
The vulnerability exists due to improper input validation in the exec command analyzer when processing allowlisted commands containing unquoted heredocs. A remote user can supply an allowlisted command with shell expansion hidden in the heredoc body to bypass exec allowlist analysis.