Junglewise Threat Intelligence

CVE-2026-53820: OpenClaw exec denylist bypass in bundle MCP loopback session-spawn

CVE-2026-53820 · Severity: medium · CVSS 6.6 · Published 2026-06-12

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a tool used for managing Gateway operations and plugins. A security flaw in its command execution path allows authorized users to bypass safety restrictions and run commands that should have been blocked. This could allow a user with limited permissions to perform unauthorized actions or gain broader control over the system than intended.

Technical details

An exec denylist bypass vulnerability exists in OpenClaw's bundle MCP loopback session-spawn path. The root cause is a failure to properly enforce command restrictions (CWE-862/CWE-284) when spawning sessions through the loopback MCP entry point. An authenticated local attacker can exploit this to execute commands that are explicitly prohibited by the configured denylist. This allows for broader command reach and potential privilege escalation within the application's trusted-operator model. The issue is addressed in version 2026.5.12; users are advised to restrict loopback access to trusted operators as a mitigation.

Affected products

  • OpenClaw OpenClaw < 2026.5.12

Timeline

  • 2026-05-28: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: CVE published to NVD

References

Related threats