PT-2026-26727 · Openclaw · Openclaw
Baozongwixd
·
Publicado
2026-03-03
·
Atualizado
2026-03-21
·
CVE-2026-32044
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.2
Description
OpenClaw is susceptible to an issue related to archive extraction within the tar.bz2 installer path. This bypasses established safety checks applied to other archive formats. An attacker can create specially crafted malicious tar.bz2 skill archives to circumvent blocking of special entries and size limitations, potentially leading to a local denial of service during skill installation.
Recommendations
Update OpenClaw to version 2026.3.2 or later.
Correção
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openclaw