


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary c…
Published:
30 maart 2026 om 22:00:00
Alert date:
31 maart 2026 om 13:04:59
Source:
nvd.nist.gov
Email & Messaging, Enterprise Applications
OpenClaw versions before 2026.3.13 contain a critical remote command injection vulnerability in the iMessage attachment staging flow. The flaw allows attackers to execute arbitrary commands on configured remote hosts by exploiting unsanitized remote attachment paths containing shell metacharacters. These malicious paths are passed directly to the SCP remote operand without proper validation. The vulnerability is only exploitable when remote attachment staging is enabled in the OpenClaw configuration. This represents a significant security risk for organizations using affected OpenClaw versions with remote attachment staging functionality.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-32917
https://github.com/openclaw/openclaw/commit/a54bf71b4c0cbe554a84340b773df37ee8e959de
https://github.com/openclaw/openclaw/security/advisories/GHSA-g2f6-pwvx-r275
https://www.vulncheck.com/advisories/openclaw-remote-command-injection-via-unsanitized-imessage-attachment-paths-in-scp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
