Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2966 articles · 183559 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-44115EXPLOITEDPATCHED
openclaw · openclaw

OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist

Description

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to execute unapproved commands at runtime.

Affected Products

VendorProductVersions
openclawopenclaw0

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-x3h8-jrgh-p8jx(vendor-advisory)
  • https://github.com/openclaw/openclaw/commit/b2e8b7d4bb2f22eaa16f5c4b07547774e90b65a5(patch)
  • https://www.vulncheck.com/advisories/openclaw-shell-expansion-bypass-in-unquoted-heredocs-via-exec-allowlist(third-party-advisory)

Related News (3 articles)

Tier D
SecurityWeek78d ago
‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery
→ No new info (linked only)
Tier D
The Hacker News81d ago
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
→ No new info (linked only)
Tier C
VulDB89d ago
CVE-2026-44115 | OpenClaw up to 2026.4.21 incomplete blacklist (GHSA-x3h8-jrgh-p8jx)
→ No new info (linked only)
CVSS 3.18.8 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
null
CWECWE-184, CWE-367
PublishedMay 6, 2026
Last enriched80d agov3
Tags
Claw Chain
Trending Score0
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-62220
OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass
Trending: 4
CRITICALCVE-2026-62198
OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search
Trending: 3
NONECVE-2026-62229EXP
OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching
Trending: 3
NONECVE-2026-62207
OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools
Trending: 3
NONECVE-2026-62223
OpenClaw < 2026.5.18 Authorization Bypass via Device-pair
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 6, 2026
Discovered by ZDM
May 6, 2026
Updated: severity, activelyExploited, patchAvailable
May 7, 2026
Actively Exploited
May 7, 2026
Patch Available
May 7, 2026
Updated: cweIds, tags
May 15, 2026

Version History

v3
Last enriched 80d ago
v3Tier D80d ago

Updated severity to HIGH, CVSS score to 9.6, added new CWE, confirmed exploit availability, and noted patch available in version 2026.4.22 with new relevant tags.

cweIdstags
via The Hacker News
v2Tier C89d ago

Updated severity to CRITICAL, marked as actively exploited, and noted that no exploit is available.

severityactivelyExploitedpatchAvailable
via VulDB
v189d ago

Initial creation