UNKNOWNCVE-2026-32978
OpenClaw < 2026.3.11 - Approval Bypass via Unrecognized Script Runners
Platform
other
Component
openclaw
Fixed in
2026.3.11
OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain script runners like tsx and jiti. Attackers can obtain approval for benign script commands, rewrite referenced scripts on disk, and execute modified code under the approved run context.
How to fix
Actualice OpenClaw a la versión 2026.3.11 o posterior. Esta versión corrige la vulnerabilidad de omisión de aprobación al vincular operandos de archivos mutables para ciertos script runners.
Monitor your dependencies automatically
Get notified when new vulnerabilities affect your projects. Free forever.
Start free