Loading market data...
← Back to CVE feed

CVE-2026-44115

HIGH CVSS 8.8 View on NVD ↗

Description

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to execute unapproved commands at runtime.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published: May 06, 2026 20:16 UTC Modified: May 06, 2026 21:20 UTC