OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.
Metrics
Affected Vendors & Products
References
History
Sat, 21 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation. | |
| Title | OpenClaw < 2026.3.2 - Tar Archive Safety Bypass in Skills Installation | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-409 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-21T00:42:18.960Z
Reserved: 2026-03-10T19:48:44.964Z
Link: CVE-2026-32044
No data.
Status : Received
Published: 2026-03-21T01:17:06.950
Modified: 2026-03-21T01:17:06.950
Link: CVE-2026-32044
No data.
OpenCVE Enrichment
No data.