Moderate severityNVD Advisory· Published Mar 19, 2026· Updated Mar 25, 2026
OpenClaw < 2026.2.24 - Approval Gating Bypass via Dispatch-Wrapper Depth-Cap Mismatch in system.run
CVE-2026-32023
Description
OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where nested transparent dispatch wrappers can suppress shell-wrapper detection. Attackers can exploit this by chaining multiple dispatch wrappers like /usr/bin/env to execute /bin/sh -c commands without triggering the expected approval prompt in allowlist plus ask=on-miss configurations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openclawnpm | < 2026.2.24 | 2026.2.24 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/openclaw/openclaw/commit/57c9a18180c8b14885bbd95474cbb17ff2d03f0bghsapatchWEB
- github.com/advisories/GHSA-ccg8-46r6-9qgjghsaADVISORY
- github.com/openclaw/openclaw/security/advisories/GHSA-ccg8-46r6-9qgjghsathird-party-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-32023ghsaADVISORY
- www.vulncheck.com/advisories/openclaw-approval-gating-bypass-via-dispatch-wrapper-depth-cap-mismatch-in-system-runghsathird-party-advisoryWEB
News mentions
0No linked articles in our index yet.