PT-2026-26727 · Openclaw · Openclaw
Baozongwixd
·
Published
2026-03-03
·
Updated
2026-03-21
·
CVE-2026-32044
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.2
Description
OpenClaw is susceptible to an issue related to archive extraction within the tar.bz2 installer path. This bypasses established safety checks applied to other archive formats. An attacker can create specially crafted malicious tar.bz2 skill archives to circumvent blocking of special entries and size limitations, potentially leading to a local denial of service during skill installation.
Recommendations
Update OpenClaw to version 2026.3.2 or later.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw