CVE-2026-53855: OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks
OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools with shell positional arguments to place inline-eval content in shell carriers outside intended allowlist rules, enabling execution of unapproved shell-provided content.
Metrics
- CVSS v4.0
- 7.6
- Severity
- HIGH
- Fixed in
- 2026.4.2
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An inline-eval allowlist bypass affects OpenClaw versions before 2026.4.2. An authenticated operator can exploit this over the network by crafting shell positional parameters that smuggle unapproved content past strict allowlist checks, placing inline-eval payloads into shell carriers that the allowlist was not designed to inspect. Successful exploitation lets the attacker execute unapproved shell-provided content and read or modify data accessible to the affected process. A patched-image rebuild at version 2026.4.2 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection for CVE-2026-53855 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication from upstream feeds, including custom-built images that package OpenClaw. Any image carrying an OpenClaw version below 2026.4.2 is flagged automatically during registry scan and CI pipeline runs.
AvailableHarborGuard scores this finding at CVSS 7.6 HIGH (v4.0) and surfaces it with that severity weighting applied against each customer organization's compliance policy. Triage routing is available to direct the alert to the appropriate team or inbox within each customer org based on configured ownership rules.
AvailableA patched-image rebuild at OpenClaw 2026.4.2 is available once an affected image is detected. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run a regression test suite against the new image, and open a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the OpenClaw service over the network to deliver the crafted request.
- AuthenticationRequired
A low-privilege operator account is sufficient; no admin credentials are needed to exploit this bypass.
- Victim interactionNot required
No user interaction is required; the attacker acts entirely on their own without involving another person.
- Attack complexityDetail
The exploit is reliable and condition-free in terms of software state, though an additional specific deployment condition (AT:P) must be present for the attack to succeed.
Blast Radius
- Reads confidential data accessible to the OpenClaw process, including configuration secrets and any stored credentials the process can reach.
- Modifies data or state reachable by the process, such as configuration files, job definitions, or persisted records.
- Executes unapproved shell content within the OpenClaw runtime, giving the attacker control over what commands run under the process identity.
- Impact is confined to the host running OpenClaw; downstream systems and availability of the service itself are not directly affected based on the CVSS scope and availability tokens.
How HarborGuard Handles This
Available on HarborGuard: detection for this CVE activates automatically against any image containing OpenClaw below 2026.4.2, with results surfaced in the registry scan dashboard and in CI pipeline checks. Where compliance policy permits auto-remediation, HarborGuard can rebuild the image at the fixed version (2026.4.2), run regression tests, and open a pull request against affected workloads; for high-severity issues, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. For environments where auto-remediation is not enabled, the finding is routed to the configured owner inbox with full CVSS detail and remediation guidance so the team can act manually. Until a rebuild is deployed, compensating controls such as network-policy rules that restrict which principals can reach the OpenClaw service and tightening operator account provisioning can reduce exposure to this authenticated bypass.
Fix available
- OpenClaw / OpenClaw< 2026.4.2 (from 0)Fixed in 2026.4.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N