CVE-2026-32065Disclosure(openclaw / openclaw)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval identity while trimming argv token whitespace, but runtime execution uses raw argv. An attacker can craft a trailing-space executable token to execute a different binary than what the approver displayed, allowing unexpected command execution under the OpenClaw runtime user when they can influence command argv and reuse an approval context.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-436

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-21: 2Technical Details · 2026-03-21: 203-21
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-32065 OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in http://system.run where rendered command text is used as approval identity while t… https://www.cve.org/CVERecord?id=CVE-2026-32065 ----- Traducción: CVE-2… http://infoflow.cloud`

    Post summary

    The post announces the CVE-2026-32065, describing an approval‑integrity bypass vulnerability in OpenClaw versions prior to 2026.2.25.

    0000032
    61 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32065 OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in http://system.run where rendered command text is used as approval identity while t… https://www.cve.org/CVERecord?id=CVE-2026-32065

    Post summary

    The excerpt refers to CVE-2026-32065 as an approval‑integrity bypass in OpenClaw, but offers no evidence of PoC, exploitation, patching, or debunking.

    00000101
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more