CVE-2026-53829: OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display
OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53829?
CVE-2026-53829 has a severity score of 8.5, classified as high risk.
How do I fix CVE-2026-53829?
To mitigate CVE-2026-53829, upgrade OpenClaw to version 2026.5.18 or later.
What does CVE-2026-53829 affect?
CVE-2026-53829 affects OpenClaw before version 2026.5.18.
What type of vulnerability is CVE-2026-53829?
CVE-2026-53829 is a command truncation vulnerability that affects the exec approval display.
Who is affected by CVE-2026-53829?
Authenticated users are affected by CVE-2026-53829 as they can exploit the vulnerability to hide command suffixes.