CVE-2026-32917
OpenClaw before version 2026.3.13 contains a remote command injection flaw in its iMessage attachment staging flow. Unsanitized attachment paths that include shell metacharacters are passed directly to the SCP command, allowing attackers to execute arbitrary commands on remote hosts. The vulnerability can be exploited without authentication or user interaction.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
OpenClaw software, specifically versions earlier than 2026.3.13, used by organizations that rely on its iMessage attachment staging feature.
Real-world impact
An attacker can run any shell command on the affected host, potentially taking full control, exfiltrating data, or installing malware. This could lead to a complete compromise of the system.
Why this severity
The CVSS score of 9.2 reflects the high impact of the vulnerability: attackers can execute arbitrary commands with no authentication or user interaction, leading to total compromise of the affected host.
What to do about it
- 01Upgrade OpenClaw to version 2026.3.13 or later.
NVD description
Timeline
- Mar 31, 2026 · Mar 31, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 25, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/openclaw/openclaw/commit/a5…patch
- github.com/openclaw/openclaw/security/…vendor advisory
- vulncheck.com/advisories/openclaw-remote-…third party advisory