HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-100559 — OpenClaw versions before 2026.8.1 contain a command parser vulnerability where e...

·Source: NIST NVD

Updated:

Executive Summary

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts.

Analysis

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts. CVSS Score: 8. Published: 2026-09-26T03:17:02.680.

Indicators of Compromise (1)

CVE (1)
CVE-2026-100559
Source Attribution

Originally published by NIST NVD on Sep 26, 2026. Verified by: NIST.

Related Threats