CVE-2026-32971

Publication date

2026-03-31 11:17:17

Family

VulnCheck

State

PUBLISHED

Description

OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve misleading command text.