PT-2026-29231 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-32971

CVSS v3.1

7.1

High

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve misleading command text.

Fix

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

CVE-2026-32971

Affected Products

Openclaw