peter bassill · operator
$ cve CVE-2026-32917 JSON

CVE-2026-32917

9.8
CRITICAL · CVSS 3.1 · EPSS 3.2% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters are passed directly to the SCP remote operand without validation, enabling command execution when remote attachment staging is enabled.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.2% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2026-03-31
Last modified2026-07-25

Affected (1)

VendorProduct
openclawopenclaw

References

→ the Explorer  ·  watch your stack  ·  NVD