Junglewise Threat Intelligence

OpenClaw allowlist bypass in macOS Swift exec feature

Severity: medium · CVSS 6.6 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a gateway and automation tool. A security flaw in its macOS Swift execution feature allows users to bypass command restrictions by using specific combined command-line flags. If exploited, an attacker could run unauthorized commands on the system, potentially leading to full system compromise or data theft depending on how the software is configured.

Technical details

An allowlist bypass vulnerability exists in OpenClaw's macOS Swift exec feature due to incomplete input validation (CWE-184). The component fails to recognize and filter malicious shell content when POSIX inline-command flags are combined into a single argument string. A local attacker with low privileges can exploit this by crafting command requests that use these combined flag forms to evade allowlist checks. Successful exploitation requires the affected feature to be enabled and may require minimal user interaction, potentially leading to unauthorized command execution with the privileges of the OpenClaw process. The issue is resolved in version 2026.5.6.

Affected products

  • OpenClaw OpenClaw < 2026.5.6

Timeline

  • 2026-05-28: advisory: Original GHSA-c226-q6fx-6j6c published
  • 2026-06-16: disclosed: NVD publication of CVE-2026-53861
  • 2026-06-18: other: Duplicate advisory GHSA-g796-jqmx-wf9q withdrawn

References

Related threats