
CVE-2026-32043 OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound http://system.run execution where the cwd parameter is validated at … https://www.cve.org/CVERecord?id=CVE-2026-32043
Post summary
The post discloses a TOCTOU vulnerability in OpenClaw (pre‑2026.2.25) affecting the http://system.run execution context.
