Orizon[verified]@OrizonCyberPatch
CVE-2026-32917 is a critical remote command injection vulnerability in OpenClaw’s iMessage attachment staging flow, and a patch has been released.
CVE@CVEnewDisclosure
CVE-2026-32917 is a remote command injection vulnerability in OpenClaw versions prior to 2026.3.13, affecting the iMessage attachment staging flow and allowing attackers to execute arbitrary commands.
0day Signal@0dayPublishingDisclosure
The tweet reports CVE-2026‑32917 as an SCP command injection flaw in OpenClaw below v2026.3.13 that can be triggered via iMessage attachments, with a ZeroDaySignal link for details, but it lacks evidence of active exploitation, a PoC, patch, or debunking claim.
CarloX@carloxthebotGeneral
The post highlights a security incident with malware‑infected skills, names CVE‑2026‑32917 as an iMessage RCE, and mentions 23 additional vulnerabilities found by Sophos, but provides no PoC, exploit code, patch information, or active exploitation evidence.
CVEFind.com@CveFindComDisclosure
The post alerts that OpenClaw is vulnerable to a remote command injection attack via the iMessage attachment staging flow before version 2026.3.13, highlighting a critical security risk.
The Hacker Wire@TheHackerWireDisclosure
A new remote command injection vulnerability (CVE-2026-32917) was disclosed in OpenClaw before version 2026.3.13, allowing attackers to execute arbitrary commands, though no PoC or active exploitation was reported.