PT-2026-29227 · Openclaw · Openclaw
Lintsinghua
·
Published
2026-03-31
·
Updated
2026-04-10
·
CVE-2026-32917
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.13
Description
OpenClaw is affected by a remote command injection issue in the iMessage attachment staging flow. The issue arises because unsanitized remote attachment paths containing shell metacharacters are passed directly to the SCP remote operand without validation. This enables command execution when remote attachment staging is enabled. The vulnerability allows attackers to execute arbitrary commands on configured remote hosts.
Recommendations
Update OpenClaw to version 2026.3.13 or later.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw