Duplicate Advisory: OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
GHSA-ffhm-8fwq-7q27
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-j472-gf56-x589. This link is maintained to preserve external references.
Original Description
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recognized by the allowlist parser. Remote authenticated operators can bypass execution allowlist checks by using unrecognized encoded-command alias forms to execute arbitrary PowerShell content.
Ready to move
Start Securing
Free, no credit card | First findings in minutes