CVE-2026-32917

CRITICAL

OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP

Title source: cna
STIX 2.1

Description

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters are passed directly to the SCP remote operand without validation, enabling command execution when remote attachment staging is enabled.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
GitHub Security Advisory (GHSA-g2f6-pwvx-r275)
https://github.com/openclaw/openclaw/security/advisories/GHSA-g2f6-pwvx-r275
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP
https://www.vulncheck.com/advisories/openclaw-remote-command-injection-via-unsanitized-imessage-attachment-paths-in-scp

Scores

CVSS v3 9.8
EPSS 0.0197
EPSS Percentile 77.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (3)
OpenClaw/OpenClaw < 2026.3.13
openclaw/openclaw < 2026.3.13
OpenClaw/OpenClaw 2026.3.13
Published Mar 31, 2026
Tracked Since Mar 31, 2026