CVE-2026-53822: OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution
OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53822?
The severity of CVE-2026-53822 is rated high, with a score of 8.7.
How do I fix CVE-2026-53822?
To fix CVE-2026-53822, upgrade to OpenClaw version 2026.5.18 or later.
What type of vulnerability is CVE-2026-53822?
CVE-2026-53822 is a command injection vulnerability.
What impact does CVE-2026-53822 have?
CVE-2026-53822 allows attackers to modify command arguments after approval, potentially bypassing security controls.
Who is affected by CVE-2026-53822?
CVE-2026-53822 affects all versions of OpenClaw prior to 2026.5.18.