CVE-2026-32921: OpenClaw < 2026.3.8 - Script Content Modification via Mutable Operand Binding in system.run
OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved script file before execution, and execute different content while maintaining the same approved command shape.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32921?
CVE-2026-32921 has been classified as a significant security vulnerability due to its potential for approval bypass in script execution.
How do I fix CVE-2026-32921?
To fix CVE-2026-32921, upgrade OpenClaw to version 2026.3.8 or later to ensure that mutable script operands are correctly bound during approval.
What versions of OpenClaw are affected by CVE-2026-32921?
CVE-2026-32921 affects OpenClaw versions prior to 2026.3.8.
What kind of vulnerability is CVE-2026-32921?
CVE-2026-32921 is an approval bypass vulnerability that allows script content modification via mutable operand binding.
Can attackers exploit CVE-2026-32921 remotely?
Yes, attackers can remotely exploit CVE-2026-32921 to gain unauthorized execution privileges in the affected versions.