top of page
perceptive_background_267k.jpg

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass all…

Published:

5 May 2026 at 22:00:00

Alert date:

6 May 2026 at 22:04:36

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools

CVE-2026-44115 affects OpenClaw versions before 2026.4.22, containing an exec allowlist analysis vulnerability. The flaw allows attackers to bypass allowlist validation by embedding shell expansion tokens in unquoted heredoc bodies. This enables execution of unapproved commands at runtime, potentially leading to unauthorized code execution. The vulnerability specifically targets the allowlist mechanism that is designed to prevent unauthorized command execution. Attackers can exploit this by hiding shell expansion within heredoc constructs that are not properly validated.

Technical details

Mitigation steps:

Affected products:

OpenClaw

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page