Vulnerability Description
OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof terminal output. Untrusted tool metadata can carry ANSI control sequences into approval prompts and permission logs, enabling attackers to manipulate displayed information through malicious tool titles.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | >= 2026.2.13, < 2026.3.25 |
Related Weaknesses (CWE)
References
- https://github.com/openclaw/openclaw/commit/464e2c10a5edceb380d815adb6ff56e1a4c5Patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-4hmj-39m8-jwc7Vendor Advisory
- https://www.vulncheck.com/advisories/openclaw-ansi-escape-sequence-injection-in-Third Party Advisory
FAQ
What is CVE-2026-35651?
CVE-2026-35651 is a vulnerability with a CVSS score of 4.3 (MEDIUM). OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof terminal output. Untrusted tool metadata can ca...
How severe is CVE-2026-35651?
CVE-2026-35651 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-35651?
Check the references section above for vendor advisories and patch information. Affected products include: Openclaw Openclaw.