CVE-2026-35651: ANSI escape injection in OpenClaw approval prompts
OpenClaw versions 2026.2.13 through 2026.3.24 are vulnerable to ANSI escape sequence injection, where untrusted tool metadata such as malicious tool titles can carry control sequences into approval prompts and permission logs to spoof terminal output. The issue was addressed in a fix commit and a GitHub security advisory.
Disclosed 10 April 2026 · Record updated 13 September 2026
Impact
Attackers could manipulate information displayed in approval prompts and permission logs, spoofing terminal output shown to users making tool-approval decisions.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-35651
