CVE-2026-32065

OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval identity while trimming argv token whitespace, but runtime execution uses raw argv. An attacker can craft a trailing-space executable token to execute a different binary than what the approver displayed, allowing unexpected command execution under the OpenClaw runtime user when they can influence command argv and reuse an approval context.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:35

Type Values Removed Values Added
Summary
  • (es) Versiones de OpenClaw anteriores a 2026.2.25 contienen una vulnerabilidad de omisión de integridad de aprobación en system.run donde el texto del comando renderizado se utiliza como identidad de aprobación mientras se recorta el espacio en blanco del token argv, pero la ejecución en tiempo de ejecución utiliza argv sin procesar. Un atacante puede crear un token ejecutable con espacio final para ejecutar un binario diferente al que mostró el aprobador, permitiendo la ejecución inesperada de comandos bajo el usuario de tiempo de ejecución de OpenClaw cuando pueden influir en el argv del comando y reutilizar un contexto de aprobación.

24 Mar 2026, 21:09

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/03e689fc89bbecbcd02876a95957ef1ad9caa176 - () https://github.com/openclaw/openclaw/commit/03e689fc89bbecbcd02876a95957ef1ad9caa176 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-hwpq-rrpf-pgcq - () https://github.com/openclaw/openclaw/security/advisories/GHSA-hwpq-rrpf-pgcq - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-approval-identity-mismatch-in-system-run-command-execution - () https://www.vulncheck.com/advisories/openclaw-approval-identity-mismatch-in-system-run-command-execution - Third Party Advisory
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

21 Mar 2026, 01:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 01:17

Updated : 2026-06-17 10:35


NVD link : CVE-2026-32065

Mitre link : CVE-2026-32065

CVE.ORG link : CVE-2026-32065


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-436

Interpretation Conflict