PT-2026-29229 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-12
·
Updated
2026-03-31
·
CVE-2026-32921
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.8
Description
The software contains an approval bypass issue in the system.run function where mutable script operands are not properly bound during the approval and execution stages. This allows attackers to gain approval for script execution, alter the approved script file before it runs, and then execute modified content while still appearing to execute the originally approved command.
Recommendations
Update to version 2026.3.8 or later.
Fix
Improper Authorization
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw