PT-2026-31962 · Openclaw · Openclaw

Keensecuritylab

+1

·

Published

2026-03-29

·

Updated

2026-04-10

·

CVE-2026-35651

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.2.13 through 2026.3.24
Description OpenClaw contains an ANSI escape sequence injection vulnerability in approval prompts. Attackers can spoof terminal output through malicious tool titles, as untrusted tool metadata can carry ANSI control sequences into approval prompts and permission logs. This allows manipulation of displayed information.
Recommendations Update to version 2026.3.25 or later.

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2026-35651
GHSA-4HMJ-39M8-JWC7

Affected Products

Openclaw