Impact
The vulnerability in OpenClaw prior to version 2026.5.18 allows an authenticated attacker to truncate the approval display of an exec command. By crafting an exec request with a benign prefix and malicious suffix that exceeds the displayed length, the attacker can conceal the true intent of the command and gain execution privileges after the approver approves a truncated command. This flaw effectively bypasses the approval process and enables the attacker to execute arbitrary operations on the system.
Affected Systems
The affected product is OpenClaw issued by OpenClaw, version 2026.5.18 and earlier. The default platform is Node.js. Only installations that expose the exec approval interface to authenticated users are susceptible.
Risk and Exploitability
With a CVSS base score of 8.5, this issue is high severity. Although the EPSS score is not available, the vulnerability is not presently listed in CISA's KEV catalog, indicating that it is not a widely exploited vulnerability. However, the flaw requires valid user credentials and the ability to submit an oversized exec command, making it likely to be leveraged in environments where users have write access to run commands. Successful exploitation would give attackers full control of the targeted system.
OpenCVE Enrichment