Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3140 articles · 161988 vulns · 38/41 feeds (7d)
← Back to list
8.8
CVE-2026-44115EXPLOITEDPATCHED
openclaw · openclaw

OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist

Description

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to execute unapproved commands at runtime.

Affected Products

VendorProductVersions
openclawopenclaw0

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-x3h8-jrgh-p8jx(vendor-advisory)
  • https://github.com/openclaw/openclaw/commit/b2e8b7d4bb2f22eaa16f5c4b07547774e90b65a5(patch)
  • https://www.vulncheck.com/advisories/openclaw-shell-expansion-bypass-in-unquoted-heredocs-via-exec-allowlist(third-party-advisory)

Related News (3 articles)

Tier D
SecurityWeek22d ago
‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery
→ No new info (linked only)
Tier D
The Hacker News25d ago
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
→ No new info (linked only)
Tier C
VulDB34d ago
CVE-2026-44115 | OpenClaw up to 2026.4.21 incomplete blacklist (GHSA-x3h8-jrgh-p8jx)
→ No new info (linked only)
CVSS 3.18.8 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
null
CWECWE-184, CWE-367
PublishedMay 6, 2026
Last enriched25d agov3
Tags
Claw Chain
Trending Score2
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-32905EXP
OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command
Trending: 16
HIGHCVE-2026-35630EXP
OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Buttons
Trending: 9
HIGHCVE-2026-35674EXP
OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route
Trending: 9
CRITICALCVE-2026-34507EXP
OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks
Trending: 8
NONECVE-2026-32906EXP
OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate
Trending: 6

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 6, 2026
Discovered by ZDM
May 6, 2026
Updated: severity, activelyExploited, patchAvailable
May 7, 2026
Actively Exploited
May 7, 2026
Patch Available
May 7, 2026
Updated: cweIds, tags
May 15, 2026

Version History

v3
Last enriched 25d ago
v3Tier D25d ago

Updated severity to HIGH, CVSS score to 9.6, added new CWE, confirmed exploit availability, and noted patch available in version 2026.4.22 with new relevant tags.

cweIdstags
via The Hacker News
v2Tier C34d ago

Updated severity to CRITICAL, marked as actively exploited, and noted that no exploit is available.

severityactivelyExploitedpatchAvailable
via VulDB
v134d ago

Initial creation