PT-2026-29227 · Openclaw · Openclaw

·

CVE-2026-32917

·

Published

2026-03-16

·

Updated

2026-07-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.13
Description A remote command injection issue exists in the iMessage attachment staging flow. The problem occurs when remote attachment staging is enabled and the software processes remote attachment paths containing shell metacharacters. These unsanitized paths are passed directly to the SCP remote operand without validation, allowing an attacker to execute arbitrary commands on configured remote hosts. The vulnerability is located in the src/auto-reply/reply/stage-sandbox-media.ts file, specifically when the ctx.MediaRemoteHost variable is set and the system spawns /usr/bin/scp using the format <remoteHost>:<remotePath>.
Recommendations Update to version 2026.3.13 or later. As a temporary mitigation, disable remote attachment staging to prevent the execution of commands via the affected flow.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32917
GHSA-G2F6-PWVX-R275

Affected Products

Openclaw