OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.
Cite this page
CVE-2026-32044. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-32044
Use CWE-409, Openclaw vendor hub and Openclaw product page to widen CVE-2026-32044 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-42426, CVE-2026-42423 and CVE-2026-42422 for nearby disclosures in the same product family.