CVE-2026-32043

OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run execution where the cwd parameter is validated at approval time but resolved at execution time. Attackers can retarget a symlinked cwd between approval and execution to bypass command execution restrictions and execute arbitrary commands on node hosts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:35

Type Values Removed Values Added
Summary
  • (es) Versiones de OpenClaw anteriores a 2026.2.25 contienen una vulnerabilidad de tiempo de verificación a tiempo de uso en la ejecución de system.run vinculada a aprobación donde el parámetro cwd es validado en el momento de la aprobación pero resuelto en el momento de la ejecución. Los atacantes pueden redirigir un cwd enlazado simbólicamente entre la aprobación y la ejecución para eludir las restricciones de ejecución de comandos y ejecutar comandos arbitrarios en los hosts de nodo.

24 Mar 2026, 19:10

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/f789f880c934caa8be25b38832f27f90f37903db - () https://github.com/openclaw/openclaw/commit/f789f880c934caa8be25b38832f27f90f37903db - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-mwcg-wfq3-4gjc - () https://github.com/openclaw/openclaw/security/advisories/GHSA-mwcg-wfq3-4gjc - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-time-of-check-time-of-use-via-mutable-symlink-in-system-run-cwd-parameter - () https://www.vulncheck.com/advisories/openclaw-time-of-check-time-of-use-via-mutable-symlink-in-system-run-cwd-parameter - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw openclaw
Openclaw

21 Mar 2026, 01:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 01:17

Updated : 2026-06-17 10:35


NVD link : CVE-2026-32043

Mitre link : CVE-2026-32043

CVE.ORG link : CVE-2026-32043


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition