CVE-2026-53853
OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern restrictions by directly invoking allowlisted executables with unrestricted arguments, potentially enabling unauthorized file access, network access, or command execution.
- Affected products
- Openclaw
- Openclaw
- < 2026.5.12
- Fix
- Available
- CVSS 3.1
- 8.3 HIGH
- EPSS
- 0.3% (27th percentile)
- Weakness
- CWE-693, CWE-863
- NVD status
- Analyzed
- Published
- 2026-06-16
CVE-2026-53853 at NVD
No indexed exploits for CVE-2026-53853 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-53853 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.