PT-2026-27242 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-23

·

Updated

2026-03-24

·

CVE-2026-32910

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.1
Description The software contains a flaw where the approval process can be bypassed, potentially allowing unauthorized binary execution. Specifically, the system.run function fails to properly bind executable identity when handling non-path-like arguments in argv[0]. This allows an attacker to modify the PATH resolution after approval, leading to the execution of a different binary than the one initially approved by the operator.
Recommendations Update to version 2026.3.1 or later.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32910

Affected Products

Openclaw