PT-2026-26240 · Openclaw+1 · Openclaw+1

Sean Nejad

·

Publicado

2026-02-19

·

Atualizado

2026-03-21

·

CVE-2026-32000

CVSS v4.0

8.6

Alta

VetorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.19 OpenClaw versions 2026.2.17 and earlier
Description OpenClaw versions prior to 2026.2.19 contain a command injection issue in the Lobster extension tool execution. This occurs due to the use of a Windows shell fallback mechanism with shell: true after process creation failures. Attackers can inject shell metacharacters into command arguments, potentially executing arbitrary commands when the subprocess launch fails with EINVAL or ENOENT errors. The issue resides in the extensions/lobster/src/lobster-tool.ts file, where the tool retries subprocess launch with shell: true on Windows for specific errors. The fix removes the shell fallback and uses explicit executable/script argv execution.
Recommendations OpenClaw versions prior to 2026.2.19 should be updated to version 2026.2.19 or later.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05004
CVE-2026-32000
GHSA-5RP4-CWGH-GVWQ
GHSA-7FCC-CW49-XM78

Produtos afetados

Blobster
Openclaw