CVE-2026-32971: OpenClaw < 2026.3.11 - Node-Host Approval UI Mismatch Allows Execution of Unintended Commands
OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve misleading command text.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32971?
CVE-2026-32971 is classified as a medium severity vulnerability due to the potential for execution of unintended commands.
How do I fix CVE-2026-32971?
To remediate CVE-2026-32971, update OpenClaw to version 2026.3.11 or later.
What type of vulnerability is CVE-2026-32971?
CVE-2026-32971 is an approval-integrity vulnerability affecting the node-host system.run approvals.
Who is affected by CVE-2026-32971?
OpenClaw versions prior to 2026.3.11 are affected by CVE-2026-32971.
What kind of attack does CVE-2026-32971 facilitate?
CVE-2026-32971 allows attackers to execute unintended commands through a mismatch in the approval UI.