PT-2026-31962 · Openclaw · Openclaw

·

CVE-2026-35651

·

Published

2026-03-29

·

Updated

2026-04-10

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.2.13 through 2026.3.24
Description OpenClaw contains an ANSI escape sequence injection vulnerability in approval prompts. Attackers can spoof terminal output through malicious tool titles, as untrusted tool metadata can carry ANSI control sequences into approval prompts and permission logs. This allows manipulation of displayed information.
Recommendations Update to version 2026.3.25 or later.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35651
GHSA-4HMJ-39M8-JWC7

Affected Products

Openclaw