HIGH 8.6 NVD

CVE-2026-100559

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to exec

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts.

References

Published: 2026-09-26 · Source: NVD · Feed updated: 2026-09-26
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-09-26 via NVD.
vulnfeed aggregates 11591 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.