CVE-2026-44115Disclosure(openclaw / openclaw)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to execute unapproved commands at runtime.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-16); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-15: 2Mentions · 2026-05-16: 3Mentions · 2026-05-18: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-15: 2Technical Details · 2026-05-16: 3Technical Details · 2026-05-18: 105-0605-0705-1505-1605-18
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Patch
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-071
Disclosure1
2026-05-152
Disclosure2
2026-05-163
Disclosure1General1Patch1
2026-05-181
Disclosure1
Full discourse8 posts
  • Mehdi Belckadi@MBelckadi
    Patch

    CVE-2026-44115 — the OpenClaw vuln leaking API keys through paths that look safe at validation time. that's NEXUM-001. we catch it statically, at the spec level, before the agent runs. 245,000 exposed instances later. the problem isn't OpenClaw. it's shipping agent access to APIs with no declared invariants. no constraints = the agent does whatever the fastest path allows. the fix isn't patching OpenClaw. it's knowing what your API allows an agent to do before it runs. a Trust Manifest doesn't prevent the vuln from existing. it prevents your API from being what gets abused. http://getnexum.dev

    Post summary

    The post details CVE‑2026‑44115, highlighting key API‑key leakage, a large number of exposed instances, and emphasizes a preventive solution based on API constraints rather than patching OpenClaw.

    00021558
    15 followersView on X
  • HumanAIFusion@humanaifusion
    Disclosure

    (4/6) CVE-2026-44115 | Heredoc Shell Expansion Bypass | CVSS 8.8 HIGH OpenClaw: $ENV vars expand inside heredocs AFTER allowlist validation passes. Hermes-Agent: Generic POSIX shell class. bash_tool is confirmed in production skill builds. Any external input → shell = live attack surface.

    Post summary

    The post announces CVE‑2026‑44115, a Heredoc Shell Expansion Bypass with CVSS 8.8, offering technical details of the flaw but no PoC, exploit, patch, or evidence of active exploitation.

    1000077
    12 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    📍 CVE-2026-44115 المشكلة بين الفحص والتنفيذ في الـ Heredoc. الفحص يشوف النص ويظن إنه نص عادي آمن. وقت التنفيذ الفعلي، بيئة التشغيل تتعامل معه بشكل ديناميكي وتنفذ متغيرات مخفية داخله. النتيجة: تسريب Tokens وAPI Keys لأن الفحص ما شاف نفس اللي شافه وقت التنفيذ.

    Post summary

    The post highlights a flaw in Heredoc handling that allows hidden variables to trigger token and API key leaks, but it provides no PoC, exploitable code, or patch information.

    10000158
    49.3K followersView on X
  • Mehdi Belckadi@MBelckadi
    General

    CVE-2026-44115 is exactly what NEXUM-001 catches at the spec level , API keys and tokens leaking through paths that look safe at validation time the issue isn't just the runtime exploit. it's that the spec never declared those credentials as protected. no declared invariants = no guardrails = the agent does whatever the fastest path allows 245k instances is what happens when you ship agent access without a Trust Manifest http://getnexum.dev

    Post summary

    The post discusses CVE‑2026‑44115 as a spec‑level credential leakage issue affecting 245k instances, without mentioning PoC, exploit code, patches, or active exploitation.

    00000508
    17 followersView on X
  • Mehdi Belckadi@MBelckadi
    Disclosure

    CVE-2026-44115 — the OpenClaw vuln leaking API keys through paths that look safe at validation time. that's NEXUM-001. we catch it statically, at the spec level, before the agent runs. 245,000 exposed instances later. the problem isn't OpenClaw. it's shipping agent access to APIs with no declared invariants. no constraints = the agent does whatever the fastest path allows. a Trust Manifest doesn't prevent the vuln from existing. it prevents your API from being what gets abused. http://getnexum.dev

    Post summary

    The statement outlines CVE‑2026‑44115 as an OpenClaw flaw leaking API keys through apparently safe paths, noting 245,000 exposed instances and attributing the issue to agent access without declared invariants, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    00000141
    17 followersView on X
  • Brandon()@brandonbango
    Disclosure

    OpenClaw Chain Vulnerabilities Expose 245,000 Public AI Agent Servers to Attack CVE-2026-44112 (CVSS 9.6 – Critical) CVE-2026-44115 (CVSS 8.8 – High) CVE-2026-44118 (CVSS 7.8 – High) CVE-2026-44113 (CVSS 7.7 – High)

    Post summary

    The announcement lists four critical and high‑severity CVEs affecting OpenClaw Chain, providing CVSS scores but no additional technical, exploit, or patch details.

    0000076
    121 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44115 OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist… https://www.cve.org/CVERecord?id=CVE-2026-44115

    Post summary

    The text announces CVE-2026-44115, providing basic technical details about an exec allowlist bypass in OpenClaw via unquoted heredoc bodies, but does not mention a PoC, exploit code, active use, or patch.

    0000078
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44115 Shell Expansion Bypass in OpenClaw Before 2026.4.22 via Heredoc Bodies https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44115

    Post summary

    The notice announces a shell expansion bypass vulnerability in OpenClaw versions prior to 2026.4.22, specifically through heredoc bodies.

    0000035
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more