CVE-2026-22175 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always grants could be circumvented through unr…
High CVSS: 7.1

CVE-2026-22175

OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always grants could be circumvented through unrecognized multiplexer shell wrappers like busybox and toybox sh -c commands. Attackers can exploit this by invoking arbitrary payloads under the same multiplexer wrapper to satisfy stored allowlist rules, bypassing intended execution restrictions.
Vendor
Openclaw
Product
Openclaw
CWE
CWE-184
Yayın Tarihi
2026-03-18 02:16:21
Güncelleme
2026-03-19 16:06:32
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar