Input validation error in OpenClaw - #VU127179

 

Input validation error in OpenClaw - #VU127179

Published: April 23, 2026


Vulnerability identifier: #VU127179
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass exec allowlist analysis.

The vulnerability exists due to improper input validation in the exec command analyzer when processing allowlisted commands containing unquoted heredocs. A remote user can supply an allowlisted command with shell expansion hidden in the heredoc body to bypass exec allowlist analysis.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.4.22

External References

Related Security Bulletins