← back
CVE-2026-32058

OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=node

CVSS 2 LOWEPSS 0.2%CWE-863
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 2EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
21 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of previously approved requests with modified environment variables. Attackers with access to an approval id can exploit this by reusing an approval with changed env input, bypassing execution-integrity controls in approval-enabled workflows.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
OpenClaw · OpenClaw

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →