Junglewise Threat Intelligence

CVE-2026-32921: OpenClaw approval bypass in system.run

CVE-2026-32921 · Severity: medium · CVSS 6.3 · Published 2026-03-31

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a platform for managing automated agents and node-host executions, contains a vulnerability where script approvals can be bypassed. An attacker with basic access can request approval for a safe script, modify the script's contents on disk after approval but before it runs, and then execute malicious code. This allows for unauthorized command execution on the host system while appearing to follow approved security workflows.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) race condition exists in the OpenClaw system.run component. The vulnerability occurs because mutable script operands (such as file paths for 'bun' or 'deno' scripts) were not bound to specific file snapshots or hashes during the approval phase. An attacker with low privileges can obtain approval for a legitimate script and then modify the underlying file on the disk before the execution phase begins. This allows the execution of arbitrary content while maintaining the 'shape' of the originally approved command. The issue is fixed in version 2026.3.8 by binding approved script operands to on-disk file snapshots.

Affected products

  • OpenClaw OpenClaw before 2026.3.8

Timeline

  • 2026-03-07: patched: Initial patch for node-host approval binding
  • 2026-03-09: patched: Follow-up patch for bun and deno script operands
  • 2026-03-31: disclosed
  • 2026-03-31: advisory

References

Related threats