---
cve: "CVE-2026-53829"
severity: "HIGH"
cvss: 8.5
epss: "0.2%"
vendor: "OpenClaw"
kev: false
exploited: false
published: "2026-06-12 22:16:54"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T02:16:15+02:00"
---

# CVE-2026-53829

> 8.5 HIGH · 🧪 PoC

## Beschreibung

OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |

## Patch verfügbar (OSV)

- 50a2481652b6a62d573ece3cead60400dc77020d (Commit)

## Referenzen

- <https://github.com/openclaw/openclaw/security/advisories/GHSA-xww8-gqvh-92x9>
- <https://www.vulncheck.com/advisories/openclaw-command-truncation-in-exec-approval-display>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-53829) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
