PT-2026-26726 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-32043

CVSS v3.1

6.5

Medium

AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run execution where the cwd parameter is validated at approval time but resolved at execution time. Attackers can retarget a symlinked cwd between approval and execution to bypass command execution restrictions and execute arbitrary commands on node hosts.

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2026-32043

Affected Products

Openclaw