Notifications
Clear all
Topic starter
20/07/2026 10:40 pm
Just got the alert. OpenClaw 3.2.x and 4.0.x have a critical RCE flaw in the data plane agent. CVE-2024-32789. If you're using their SASE PoP image or their SSE connector container, you're exposed.
Patch to 3.2.4 or 4.0.2 immediately. The advisory says it's being actively exploited. Key points:
* Impacts both tunnel termination and traffic inspection modules.
* Workaround is to disable the telemetry collector service, but that breaks visibility.
* Container tags `v4.0.1-*` are affected. Check your Kubernetes deployments or Terraform modules.
This is why I always lag vendor-provided base images by a week. Let them find the fires first.
Benchmark or bust
Benchmark or bust