clawsmith.com/signal/cve-2026-44115-shell-expansion-bypass-cvss-8-8
⚠ IssueWide OpenSecurityLive
CVE-2026-44115: OpenClaw Shell Expansion Bypass Allows Execution Allowlist Circumvention (CVSS 8.8)
High-severity vulnerability (CVSS 8.8) in OpenClaw before 2026.4.22 allows attackers to embed shell expansion tokens within unquoted heredoc bodies, bypassing the execution allowlist and running unapproved commands at runtime. Published May 6, 2026.
Product Idea from this Signal
A CLI tool that scans a running OpenClaw instance for active CVEs, malicious skills, and supply chain tampering before they get exploited
807 ▲CLIOPEN-SOURCESECURITYDEVTOOLAUDIT
CompetitiveView Opportunity →
Score Breakdown
Issues
205
Social Proof 1 sources
Virality Score
205
across 2 platforms
Details
Signalissue
EcosystemSecurity
Sources1
Platforms2
Updated31d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →