Metrics
Affected Vendors & Products
Fri, 03 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails to recognize. Attackers can craft commands such as piped execution, command substitution, or subshell invocation to bypass the validateScriptFileForShellBleed() validation checks and execute arbitrary script content that would otherwise be blocked. | |
| Title | OpenClaw - Shell-Bleed Protection Preflight Validation Bypass | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-184 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-03T13:00:31.471Z
Reserved: 2026-03-27T15:24:06.752Z
Link: CVE-2026-34425
Updated: 2026-04-03T13:00:28.163Z
Status : Awaiting Analysis
Published: 2026-04-02T19:21:31.507
Modified: 2026-04-03T16:10:23.730
Link: CVE-2026-34425
No data.
OpenCVE Enrichment
Updated: 2026-04-03T09:16:55Z