5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Description
OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof terminal output. Untrusted tool metadata can carry ANSI control sequences into approval prompts and permission logs, enabling attackers to manipulate displayed information through malicious tool titles.
Basic Information
ID
CVE-2026-35651
Source
VulnCheck
Published
Apr 10, 2026 at 16:03
Affected Product
Vendor
OpenClaw
Product
OpenClaw
Version
2026.2.13
Affected Versions
OpenClaw OpenClaw 2026.2.13