Skip to content

OpenClaw has an exec allowlist bypass via command substitution/backticks inside double quotes

High severity GitHub Reviewed Published Feb 14, 2026 in openclaw/openclaw • Updated Mar 6, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts