MEDIUM
OpenClaw < 2026.3.2 - Tar Archive Safety Bypass in Skills Installation
Published Mar 21, 2026
6.7
MEDIUMCVSS 4.0
EPSS 0.19%
Description
OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.
Affected products
-
Affected
- ≥ 0, < 2026.3.2
Unaffected
- 2026.3.2
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-13937 Advisory
- https://github.com/openclaw/openclaw/commit/0dbb92dd2bcf9a32379d11c0f11ed016669dae3e patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-77hf-7fqf-f227 vendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-tar-archive-safety-bypass-in-skills-installation third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-13937 | Advisory | |
| https://github.com/openclaw/openclaw/commit/0dbb92dd2bcf9a32379d11c0f11ed016669dae3e | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-77hf-7fqf-f227 | vendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-tar-archive-safety-bypass-in-skills-installation | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 21, 2026
Updated Jun 23, 2026
Reserved Mar 10, 2026
Link CVE-2026-32044
CISA Vulnrichment
Updated Mar 23, 2026
Red Hat
No data
GitHub
No data