9.2
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters are passed directly to the SCP remote operand without validation, enabling command execution when remote attachment staging is enabled.
Basic Information
ID
CVE-2026-32917
Source
VulnCheck
Published
Mar 31, 2026 at 11:17
Modified
Mar 31, 2026 at 13:31
Affected Product
Vendor
OpenClaw
Product
OpenClaw
Affected Versions
OpenClaw OpenClaw 0