Medium severity6.5NVD Advisory· Published Mar 21, 2026· Updated Jun 17, 2026
CVE-2026-32043
CVE-2026-32043
Description
OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run execution where the cwd parameter is validated at approval time but resolved at execution time. Attackers can retarget a symlinked cwd between approval and execution to bypass command execution restrictions and execute arbitrary commands on node hosts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openclawnpm | < 2026.2.25 | 2026.2.25 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/openclaw/openclaw/commit/f789f880c934caa8be25b38832f27f90f37903dbnvdPatchWEB
- github.com/advisories/GHSA-mwcg-wfq3-4gjcghsaADVISORY
- github.com/openclaw/openclaw/security/advisories/GHSA-mwcg-wfq3-4gjcnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-32043ghsaADVISORY
- www.vulncheck.com/advisories/openclaw-time-of-check-time-of-use-via-mutable-symlink-in-system-run-cwd-parameternvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.