CVE-2026-32921

MEDIUM

OpenClaw < 2026.3.8 - Script Content Modification via Mutable Operand Binding in system.run

Title source: cna
STIX 2.1

Description

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved script file before execution, and execute different content while maintaining the same approved command shape.

References (4)

Core 4
Core References
Third Party Advisory third-party-advisory
GitHub Security Advisory (GHSA-8g75-q649-6pv6)
https://github.com/openclaw/openclaw/security/advisories/GHSA-8g75-q649-6pv6
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.3.8 - Script Content Modification via Mutable Operand Binding in system.run
https://www.vulncheck.com/advisories/openclaw-script-content-modification-via-mutable-operand-binding-in-system-run

Scores

CVSS v3 6.3
EPSS 0.0020
EPSS Percentile 9.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-367
Status published
Products (4)
npm/openclaw 0 - 2026.3.8npm
OpenClaw/OpenClaw < 2026.3.8
openclaw/openclaw < 2026.3.8
OpenClaw/OpenClaw 2026.3.8
Published Mar 31, 2026
Tracked Since Mar 31, 2026