CVE-2026-53829EPSS p14.1%

CVE-2026-53829CVE-2026-53829

openclaw / openclaw

Description

OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.

Scoring

CVSS 8.0 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS0.23% probability of exploitation · percentile 14.1% · 2026-08-03T12:00:16Z
Last modified2026-07-23
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.