Report: CVE-2026-32979 - OpenClaw < 2026.3.11 - Unbound Interpreter and Runtime Commands Bypass in node-h

Report: CVE-2026-32979 - OpenClaw < 2026.3.11 - Unbound Interpreter and Runtime Commands Bypass in node-h

CVE ID :CVE-2026-32979 Published : March 29, 2026, 1:17 p.m. | 1 hour, 33 minutes ago Description :OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local code by modifying scripts between approval and execution when exact file binding cannot occur. Remote attackers can change approved local scripts before execution to achieve unintended code execution as the OpenClaw runtime user. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
March 29, 2026
Attack Vector: local
Impact: code execution