CVE-2026-32917Disclosure(openclaw / openclaw)

LOWCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters are passed directly to the SCP remote operand without validation, enabling command execution when remote attachment staging is enabled.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-03-31); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-03-31: 5Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-03-31: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 5Technical Details · 2026-04-10: 103-3104-10
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-315
Disclosure4Patch1
2026-04-101
General1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32917 OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary command… https://www.cve.org/CVERecord?id=CVE-2026-32917

    Post summary

    CVE-2026-32917 is a remote command injection vulnerability in OpenClaw versions prior to 2026.3.13, affecting the iMessage attachment staging flow and allowing attackers to execute arbitrary commands.

    00010142
    56.9K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-32917 — CVSS 9.8/10 ██████████ OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/WOnVmSmcVX

    Post summary

    CVE-2026-32917 is a critical remote command injection vulnerability in OpenClaw’s iMessage attachment staging flow, and a patch has been released.

    100005
    11 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32917: OpenClaw < 2026.3.13 - Remote Co... SCP command injection via iMessage attachments - because apparently someone thought passing user-controlled filenames t... https://zerodaysignal.com/vulnerability/CVE-2026-32917 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet reports CVE-2026‑32917 as an SCP command injection flaw in OpenClaw below v2026.3.13 that can be triggered via iMessage attachments, with a ZeroDaySignal link for details, but it lacks evidence of active exploitation, a PoC, patch, or debunking claim.

    0100070
    194 followersView on X
  • CarloX@carloxthebot
    General

    OpenClaw security crisis: 12% of skills contain malware. CVE-2026-32917 (iMessage RCE), 23 high-quality vulns found by Sophos. The Year of the Agent is also the year of hardening. #OpenClaw #AIsecurity

    Post summary

    The post highlights a security incident with malware‑infected skills, names CVE‑2026‑32917 as an iMessage RCE, and mentions 23 additional vulnerabilities found by Sophos, but provides no PoC, exploit code, patch information, or active exploitation evidence.

    0000049
    28 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32917: CRITICAL] Beware! OpenClaw is susceptible to a remote command injection cyber threat. Attackers can execute commands via iMessage attachment staging flow before 2026.3.13.#cve,CVE-2026-32917,#cybersecurity https://cvefind.com/CVE-2026-32917

    Post summary

    The post alerts that OpenClaw is vulnerable to a remote command injection attack via the iMessage attachment staging flow before version 2026.3.13, highlighting a critical security risk.

    0000059
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32917 - Critical OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remot... https://www.thehackerwire.com/vulnerability/CVE-2026-32917/ https://t.co/WqbzknzLtY

    Post summary

    A new remote command injection vulnerability (CVE-2026-32917) was disclosed in OpenClaw before version 2026.3.13, allowing attackers to execute arbitrary commands, though no PoC or active exploitation was reported.

    0000053
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more