CVE-2026-32046 is a critical improper sandbox configuration vulnerability affecting OpenClaw versions prior to 2026.2.21. This flaw allows attackers to execute arbitrary code on the host system by exploiting renderer-side vulnerabilities, bypassing OS-level sandbox protections within the Chromium browser container. With a CVSS score of 9.8, it is easily exploitable over the network without user interaction or privileges, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the severe nature of this vulnerability warrants immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.2.21CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.2.21CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.