Input validation error in OpenClaw - #VU132729

 

Input validation error in OpenClaw - #VU132729

Published: May 29, 2026


Vulnerability identifier: #VU132729
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute shell content outside the intended allowlist check.

The vulnerability exists due to improper input validation in the macOS Swift exec allowlist logic when processing command requests using combined POSIX inline-command flags. A local user can send a specially crafted command request to execute shell content outside the intended allowlist check.

Only instances where the affected feature is enabled and reachable are vulnerable. User interaction is required.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.5.6

External References

Related Security Bulletins