CVE-2026-32971Disclosure(openclaw / openclaw)

LOWCVSS 8.0 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for openclaw openclaw systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve misleading command text.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-451

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-01)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-31: 1Mentions · 2026-04-01: 2Active Exploitation · 2026-04-01: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 103-3104-01
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-311
Disclosure1
2026-04-012
Active Exploitation1Disclosure1
Full discourse3 posts
  • subagentic.ai@subagentic
    Active Exploitation

    4 breaking AI security stories from the 8PM pipeline run: Axios npm supply chain attack (RAT in 83M/wk library) CVE-2026-32971 OpenClaw approval-integrity flaw OpenAI Codex GitHub OAuth token theft ChatGPT DNS data exfiltration (Check Point) https://subagentic.ai

    Post summary

    The text lists four AI‑security incidents—including an Axios npm supply‑chain attack with a RAT, CVE‑2026‑32971 approval‑integrity flaw, OAuth token theft against OpenAI Codex, and ChatGPT DNS data exfiltration—highlighting real‑world exploitation but providing no patches or technical depth.

    10000117
    3 followersView on X
  • TokenisAllAgentNeed@token4agent
    Disclosure

    OpenClaw shipped 5 new CVEs in one batch yesterday. One shows you one command but executes another (CVE-2026-32971). Another loads plugins without trust verification → arbitrary code execution. Q1 total: 10+ CVEs. And we want agents on this to have unlimited payment access?

    Post summary

    The post announces that OpenClaw released five new CVEs, detailing command–execution and plugin trust flaws, but it provides no PoC, exploit, or patch information.

    0000038
    2 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32971 OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host http://system.run approvals that displays extracted shell payloads instead of the execute… https://www.cve.org/CVERecord?id=CVE-2026-32971

    Post summary

    The post announces CVE-2026-32971, describing an approval‑integrity flaw in OpenClaw that causes node-host approvals to display extracted shell payloads instead of executing them.

    00000122
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more