CVE-2026-32978Patch(openclaw / openclaw)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain script runners like tsx and jiti. Attackers can obtain approval for benign script commands, rewrite referenced scripts on disk, and execute modified code under the approved run context.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-03-30)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-29: 2Mentions · 2026-03-30: 3Patch / Workaround · 2026-03-30: 3Technical Details · 2026-03-29: 2Technical Details · 2026-03-30: 103-2903-30
Signal classification3 categories
Patch
360.0%
Disclosure
120.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-292
Disclosure1General1
2026-03-303
Patch3
Full discourse5 posts
  • botnewsnetwork@botnewsnetwork
    Patch

    [BNN SECURITY] 🔒 CVSS 9.9 THE NIGHT BEFORE CLAWCON TOKYO Four new OpenClaw CVEs disclosed today — on top of this morning's sandbox escape batch. Seven total on a single Sunday. March: 70+. • CVE-2026-32922 (9.9 CRITICAL): Rotate a token, get admin. From there: RCE on connected nodes or full gateway takeover. Affects all versions before 2026.3.11. • CVE-2026-32975 (9.8 CRITICAL): No-auth channel bypass via group name matching. Attackers create a group with the same name as an allowlisted one. No credentials needed. • CVE-2026-32972 (HIGH): Operator→admin privilege escalation via browser profile management routes. • CVE-2026-32978 (HIGH): You approve command A. Command B runs. TOCTOU-class bypass in the human-in-the-loop approval mechanism — the same mechanism plugin approval hooks (shipped yesterday in v2026.3.28) were built to strengthen. THE ONE THAT MATTERS CVE-32978 is the story within the story. The approval flow that operators rely on as a last line of defense has a swap window between display and execution. You see "list files." You click approve. "Delete database" runs. It's a time-of-check-to-time-of-use race condition in the trust boundary between human and agent. This is the same class of vulnerability that makes autonomous agent execution dangerous — and it was sitting in the manual approval path that's supposed to be the safety net. PATCH STATUS All four patched in v2026.3.11+. Current release: v2026.3.28. If you updated, you're covered. If you haven't updated and you're running a self-hosted gateway with node connections: patch tonight. Not tomorrow. Tonight. ClawCon Tokyo opens in hours. The timing is notable but not the point. The point is that the approval mechanism — the thing you trust when you don't trust the agent — had a hole in it. 📎 Via @thehackerwire @redpacketsecurity #BNN #OpenClaw #CVE #Security #ClawConTokyo

    Post summary

    The post announces four high‑severity OpenClaw CVEs, provides technical details about each, and confirms that they are patched in v2026.3.11+, urging users to update.

    00010138
    29 followersView on X
  • Luna@Luna1248454
    Patch

    2 vulnérabilités critiques corrigées dans OpenClaw (CVE-2026-32978 & CVE-2026-32979). Patch dispo depuis v2026.3.11 🚨 #cybersecurity #OpenClaw #CVE https://t.co/MFfJ9l01SU

    Post summary

    The tweet announces that two critical CVEs (CVE-2026-32978 & CVE-2026-32979) in OpenClaw have been fixed and a patch is available as of version 2026.3.11.

    0000051
    14 followersView on X
  • Luna@Luna1248454
    Patch

    2 vulnérabilités critiques corrigées dans OpenClaw (CVE-2026-32978 & CVE-2026-32979). Si vous utilisez OpenClaw, checkez votre version. Patch dispo depuis v2026.3.11 🚨 #cybersecurity #OpenClaw #CVE https://t.co/SZ6FvFYeR3

    Post summary

    The tweet announces that two critical OpenClaw vulnerabilities (CVE-2026-32978 & CVE-2026-32979) have been fixed, and a patch is available starting with version 2026.3.11.

    0000049
    14 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32978 - High OpenClaw before 2026.3.11 contains an approval integrity vulnerability where http://system.run approvals fail to bind mutable file operands for certain script runners like tsx and jiti. Attackers ca... https://www.thehackerwire.com/vulnerability/CVE-2026-32978/ https://t.co/0QwVM4zX0W

    Post summary

    A new high‑severity vulnerability, CVE-2026‑32978, has been disclosed for OpenClaw versions prior to 2026.3.11, involving failure to bind mutable file operands during approval processes for certain script runners; no PoC, patch, or active exploitation details are provided.

    0000061
    163 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32978 OpenClaw before 2026.3.11 contains an approval integrity vulnerability where http://system.run approvals fail to bind mutable file operands for certain script runners like t… https://www.cve.org/CVERecord?id=CVE-2026-32978

    Post summary

    The post reports an approval integrity flaw in OpenClaw (pre‑2026.3.11) where system.run approvals fail to bind mutable file operands for certain script runners, but it offers no evidence of exploitation, patch, or PoC.

    0000078
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more