PT-2026-27242 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-23
·
Updated
2026-03-24
·
CVE-2026-32910
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.1
Description
The software contains a flaw where the approval process can be bypassed, potentially allowing unauthorized binary execution. Specifically, the
system.run function fails to properly bind executable identity when handling non-path-like arguments in argv[0]. This allows an attacker to modify the PATH resolution after approval, leading to the execution of a different binary than the one initially approved by the operator.Recommendations
Update to version 2026.3.1 or later.
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw