Tag
high
threat
OpenClaw Exec Approval Truncation Vulnerability
2 TTPsA high-severity vulnerability in OpenClaw's exec approval feature (versions prior to 2026.5.18) allows an authenticated attacker to bypass approval integrity by crafting a long command that appears benign in the truncated UI but contains a malicious suffix, leading to unauthorized command execution.
exploited
npm/openclaw
command-injection
approval-bypass
integrity-compromise
application
2t
high
advisory
OpenClaw Approval Integrity Vulnerability Leads to Code Execution (CVE-2026-32971)
2 rules 1 TTP 1 CVEOpenClaw before 2026.3.11 exhibits an approval-integrity vulnerability where attackers can place wrapper binaries to execute local code after operators approve misleading command text, due to the system displaying extracted shell payloads instead of the actual executed arguments.
cve-2026-32971
code-execution
approval-bypass
2r
1t
1c