Executive brief
OpenClaw is a gateway and command execution tool. A security flaw allows authorized users to bypass command restrictions by using "transparent command wrappers." This could allow a user to perform unauthorized actions or system modifications that should have been blocked by the security allowlist.
Technical details
OpenClaw before version 2026.5.26 is vulnerable to an allowlist bypass (CWE-184/CWE-78) in its command execution path. The vulnerability occurs when the system evaluates an inner command against the allowlist while the outer wrapper invocation still executes, leading to unintended side effects. An authenticated operator with network access can craft specific command requests to leverage these transparent wrappers and perform operations outside the intended security policy. The issue is resolved in version 2026.5.26.
Affected products
- OpenClaw openclaw < 2026.5.26
Timeline
- 2026-05-28: advisory: Original GHSA-cwpp-5962-q4f6 published
- 2026-06-16: disclosed: NVD and VulnCheck publication
- 2026-06-18: other: Duplicate advisory GHSA-wrr6-p5r6-474m withdrawn