Description
OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated callers to bypass intended command restrictions. Attackers can reach the affected bundled MCP session-spawn path to start sessions with broader command reach than intended.
Published: 2026-06-12
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw before 2026.5.12 contains an exec denylist bypass that permits authenticated callers to circumvent the intended command restrictions, enabling the spawning of sessions with wider command capabilities. This flaw is a classic example of improper authorization (CWE‑862) and allows attackers to execute commands beyond the intended scope. The vulnerability arises from the bundle MCP loopback session‑spawn path, which accepts commands that should be blocked by the application's denylist. The impact of this flaw is the potential for an authenticated attacker to run arbitrary commands with elevated privileges, leading to compromise of confidentiality, integrity, and availability of the affected system. Because the attacker must be authenticated, the risk is limited to accounts with compromised or privileged access, but any successful exploitation effectively lifts the command restrictions the application attempts to enforce. Risk and exploitability are moderate. The CVSS score of 6.9 indicates a high severity vulnerability, and the absence of an EPSS score and KEV listing suggests that widespread exploitation has not yet been observed. Successful exploitation requires access to the bundle MCP session‑spawn endpoint, so securing or restricting this path is critical to mitigating the threat.

Affected Systems

OpenClaw OpenClaw, versions prior to 2026.5.12 are affected.

Risk and Exploitability

The CVSS score of 6.9 reflects a significant risk that, combined with the lack of current exploitation data, indicates a moderate to high threat level. Attackers need authenticated access to the bundle MCP loopback session‑spawn path; once obtained, they can bypass the exec denylist and run arbitrary commands. As the flaw is not listed in CISA KEV, no known active campaigns are reported currently.

Generated by OpenCVE AI on June 12, 2026 at 23:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to version 2026.5.12 or newer where the exec denylist bypass is fixed.
  • Configure the application to enforce strict authorization checks on the bundle MCP session‑spawn endpoint, ensuring only privileged users can access it.
  • If an update is not immediately available, disable or limit the loopback session‑spawn functionality and monitor for unauthorized access attempts.

Generated by OpenCVE AI on June 12, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 12 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Description OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated callers to bypass intended command restrictions. Attackers can reach the affected bundled MCP session-spawn path to start sessions with broader command reach than intended.
Title OpenClaw < 2026.5.12 - Exec Denylist Bypass in Bundle MCP Loopback Session Spawn
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-862
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-12T21:56:48.856Z

Reserved: 2026-06-10T21:16:07.495Z

Link: CVE-2026-53820

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-12T22:16:53.027

Modified: 2026-06-12T22:16:53.027

Link: CVE-2026-53820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-13T01:00:06Z

Weaknesses