Skip to main content
Loading…
    CVE-2026-31997 — OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run approvals, allowing post-approval executable rebind attacks. Attackers can modify PAT — CVE Database · The Intelligence Room