Executive brief
OpenClaw is a tool used for managing command execution and gateway operations. A security flaw on macOS allows certain commands to bypass the safety allowlist by using specific combined command flags. This could allow an attacker to run unauthorized shell commands, potentially leading to data exposure or unauthorized system changes.
Technical details
A vulnerability exists in OpenClaw's macOS Swift execution allowlist due to incomplete input validation (CWE-184). The allowlist logic fails to account for combined POSIX inline-command flags, which can be used to hide or misrepresent command content during the validation process. An attacker with local access and low privileges can exploit this by crafting command requests that use these combined flags to bypass allowlist checks. This allows for the execution of arbitrary shell content outside of the intended security policy. The issue is fixed in version 2026.5.6.
Affected products
- openclaw openclaw <= 2026.5.5
Timeline
- 2026-05-28: disclosed
- 2026-06-18: advisory
- 2026-06-18: patched: Version 2026.5.6 released