CVE-2026-32921: OpenClaw < 2026.3.8 - Script Content Modification via Mutable Operand Binding in system.run

Published Mar 31, 2026
·
Updated

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved script file before execution, and execute different content while maintaining the same approved command shape.

Affected Software

2 affected components
OpenClaw OpenClaw<2026.3.8
OpenClaw Openclaw Node.js<2026.3.8

Event History

Mar 31, 2026
CVE Published
via MITRE·11:17 AM
Data Sourced
via MITRE·11:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-32921?

CVE-2026-32921 has been classified as a significant security vulnerability due to its potential for approval bypass in script execution.

2

How do I fix CVE-2026-32921?

To fix CVE-2026-32921, upgrade OpenClaw to version 2026.3.8 or later to ensure that mutable script operands are correctly bound during approval.

3

What versions of OpenClaw are affected by CVE-2026-32921?

CVE-2026-32921 affects OpenClaw versions prior to 2026.3.8.

4

What kind of vulnerability is CVE-2026-32921?

CVE-2026-32921 is an approval bypass vulnerability that allows script content modification via mutable operand binding.

5

Can attackers exploit CVE-2026-32921 remotely?

Yes, attackers can remotely exploit CVE-2026-32921 to gain unauthorized execution privileges in the affected versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203