PT-2026-26240 · Openclaw+1 · Openclaw+1
Sean Nejad
·
Publicado
2026-02-19
·
Atualizado
2026-03-21
·
CVE-2026-32000
CVSS v4.0
8.6
Alta
| Vetor | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.19
OpenClaw versions 2026.2.17 and earlier
Description
OpenClaw versions prior to 2026.2.19 contain a command injection issue in the Lobster extension tool execution. This occurs due to the use of a Windows shell fallback mechanism with
shell: true after process creation failures. Attackers can inject shell metacharacters into command arguments, potentially executing arbitrary commands when the subprocess launch fails with EINVAL or ENOENT errors. The issue resides in the extensions/lobster/src/lobster-tool.ts file, where the tool retries subprocess launch with shell: true on Windows for specific errors. The fix removes the shell fallback and uses explicit executable/script argv execution.Recommendations
OpenClaw versions prior to 2026.2.19 should be updated to version 2026.2.19 or later.
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Blobster
Openclaw