
CVE-2026-32921 OpenClaw before 2026.3.8 contains an approval bypass vulnerability in http://system.run where mutable script operands are not bound across approval and execution phases. Att… https://www.cve.org/CVERecord?id=CVE-2026-32921
Post summary
The tweet announces CVE‑2026‑32921, an approval bypass flaw in OpenClaw’s system.run component that occurs because mutable script operands aren’t correctly bound between approval and execution. No PoC, exploit code, patch, or active exploitation detail is provided.

