PT-2026-29227 · Openclaw · Openclaw

Lintsinghua

·

Published

2026-03-31

·

Updated

2026-04-10

·

CVE-2026-32917

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.13
Description OpenClaw is affected by a remote command injection issue in the iMessage attachment staging flow. The issue arises because unsanitized remote attachment paths containing shell metacharacters are passed directly to the SCP remote operand without validation. This enables command execution when remote attachment staging is enabled. The vulnerability allows attackers to execute arbitrary commands on configured remote hosts.
Recommendations Update OpenClaw to version 2026.3.13 or later.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-32917

Affected Products

Openclaw