CVE-2026-53845
EUVD-2026-3714716.06.2026, 19:17
OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch path skip before-tool-call hook coverage. Attackers can exploit this by sending skill commands through the vulnerable dispatch path to bypass hook-based auditing and policy enforcement mechanisms.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openclaw | openclaw | 𝑥 < 2026.5.6 |
| openclaw | openclaw | 2026.5.6:beta1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration