CVE-2026-53855 – OpenClaw < 2026.4.2 – Shell Positional Parameters Bypass in Inline-Eval Checks

​CVE ID :CVE-2026-53855

Published : June 16, 2026, 6:05 p.m. | 30 minutes ago

Description :OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools with shell positional arguments to place inline-eval content in shell carriers outside intended allowlist rules, enabling execution of unapproved shell-provided content.

Severity: 8.1 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More