Security Advisory

CVE-2026-53861

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-16 18:05:07
Last updated 2026-06-18 03:56:04
Assigner VulnCheck
CVSS score 5.3
State PUBLISHED

Description

OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. Attackers can execute shell content outside the intended allowlist check by using combined flag forms, potentially allowing unauthorized command execution depending on operator configuration.