


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass all…
Published:
5 mei 2026 om 22:00:00
Alert date:
6 mei 2026 om 22:04:36
Source:
nvd.nist.gov
Security Tools
CVE-2026-44115 affects OpenClaw versions before 2026.4.22, containing an exec allowlist analysis vulnerability. The flaw allows attackers to bypass allowlist validation by embedding shell expansion tokens in unquoted heredoc bodies. This enables execution of unapproved commands at runtime, potentially leading to unauthorized code execution. The vulnerability specifically targets the allowlist mechanism that is designed to prevent unauthorized command execution. Attackers can exploit this by hiding shell expansion within heredoc constructs that are not properly validated.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44115
https://github.com/openclaw/openclaw/commit/b2e8b7d4bb2f22eaa16f5c4b07547774e90b65a5
https://github.com/openclaw/openclaw/security/advisories/GHSA-x3h8-jrgh-p8jx
https://www.vulncheck.com/advisories/openclaw-shell-expansion-bypass-in-unquoted-heredocs-via-exec-allowlist
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
