CVE-2026-32971
OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve misleading command text.
Vendor
Product
CWE
Yayın Tarihi
2026-03-31 12:16:29
Güncelleme
2026-04-02 14:14:43
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-