CVE-2026-32917

CRITICAL

OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP

Title source: cna

Description

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters are passed directly to the SCP remote operand without validation, enabling command execution when remote attachment staging is enabled.

Scores

CVSS v3 9.8
EPSS 0.0059
EPSS Percentile 69.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (3)
OpenClaw/OpenClaw < 2026.3.13
openclaw/openclaw < 2026.3.13
OpenClaw/OpenClaw 2026.3.13
Published Mar 31, 2026
Tracked Since Mar 31, 2026