CVE-2026-32060Disclosure(openclaw / openclaw)

MEDIUMCVSS 8.7 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configured workspace directory. When apply_patch is enabled without filesystem sandbox containment, attackers can exploit crafted paths including directory traversal sequences or absolute paths to escape workspace boundaries and modify arbitrary files.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-11); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-12: 1Mentions · 2026-03-15: 2Mentions · 2026-03-17: 1Active Exploitation · 2026-03-11: 1Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-15: 2Technical Details · 2026-03-11: 3Technical Details · 2026-03-15: 1Technical Details · 2026-03-17: 103-1103-1203-1503-17
Signal classification4 categories
Disclosure
342.9%
General
228.6%
Active Exploitation
114.3%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-113
Active Exploitation1Disclosure2
2026-03-121
General1
2026-03-152
Disclosure1Patch1
2026-03-171
General1
Full discourse7 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32060 OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configured works… https://www.cve.org/CVERecord?id=CVE-2026-32060

    Post summary

    The text announces a path traversal flaw in OpenClaw versions before 2026.2.14, noting that the vulnerability enables file writes or deletions beyond the intended workspace.

    10010126
    56.7K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-32060: OpenClaw apply_patch Path Traversal Bug - What It Means for Your Business and How to Respond https://hubs.li/Q047ddmP0

    Post summary

    The article highlights CVE-2026-32060, a path traversal flaw in OpenClaw’s apply_patch, but does not provide detailed technical or mitigation information beyond the title.

    0000045
    29 followersView on X
  • ClawHost@tryclawhost
    Patch

    @CVEnew Good to stay updated on vulnerabilities like CVE-2026-32060. If you run OpenClaw on your own dedicated server with ClawHost, you get easy one-click version switching and rollbacks, so you can patch or switch versions fast while keeping full control.

    Post summary

    The note highlights that CVE‑2026‑32060 can be mitigated by quickly patching through one‑click version switching in OpenClaw’s ClawHost, with no evidence of active exploitation or PoC available.

    0000047
    251 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-32060 - openclaw - openclaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-32060-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-32060 #openclaw #

    Post summary

    The post announces a CVE alert for CVE-2026-32060 with a link to an external page, but provides no additional details or actionable information about the vulnerability.

    0000095
    3.5K followersView on X
  • botnewsnetwork@botnewsnetwork
    Active Exploitation

    🚨 THE ATTACK SURFACE WIDENED OVERNIGHT: NEW OPENCLAW CVEs, RUST SUPPLY CHAIN, CHINA'S SECOND WARNING Two new HIGH severity CVEs disclosed today: → CVE-2026-32060: Path traversal in apply_patch — write or delete files outside your workspace. Patch: 2026.2.14+ → CVE-2026-32059: GNU long-option bypass in safeBins sort validation. Patch: 2026.2.22-2+ Endor Labs audited OpenClaw independently: 6 additional vulnerabilities found — SSRF, missing authentication, more path traversal. This is a sustained audit wave, not isolated bugs. Supply chain now hitting developer toolchain (CVE-2026-28353): 5 malicious Rust crates on http://crates.io targeting AI coding CLIs — delivered via weaponized Open VSX extension (v1.8.12-1.8.13). After npm (14K downloads) and ClawHub (341 skills), attackers are inside the IDE extension layer. China's CNCERT/CC just issued its second OpenClaw advisory in 72 hours — following MIIT's Monday warning. Now the national cybersecurity coordination center is flagging prompt injection, insufficient permissions, and default config data leaks. The 72-hour escalation: → npm supply chain → ClawHub (341 compromised skills) → Two new core CVEs → Rust crate toolchain attack → Two nation-state advisories Every layer is live. Update OpenClaw now. Audit every extension and crate in your build chain. #BNN #AgentSecurity #OpenClaw #CVE #SupplyChain

    Post summary

    The post discloses two high‑severity OpenClaw CVEs, additional related vulnerabilities, and a supply‑chain attack via malicious Rust crates, while asserting these weaknesses are actively exploited and urging immediate patching.

    0000040
    25 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32060: HIGH] Cyber security alert: OpenClaw versions before 2026.2.14 vulnerable to path traversal flaw. Attackers can write/delete files outside workspace boundaries. Apply update ASAP!#cve,CVE-2026-32060,#cybersecurity https://cvefind.com/CVE-2026-32060

    Post summary

    OpenClaw versions prior to 2026.2.14 are vulnerable to a path traversal bug that permits file write/delete beyond workspace limits; an update is urgently recommended.

    0000052
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32060 - High OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configured workspace directory. When appl... https://www.thehackerwire.com/vulnerability/CVE-2026-32060/ https://t.co/Vy2ndvWGZA

    Post summary

    The tweet announces a high‑severity path‑traversal flaw in OpenClaw versions prior to 2026.2.14, enabling attackers to write or delete files outside the workspace, with further details available via the linked article.

    0000054
    134 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more