PT-2026-26240 · Lobster+1 · Blobster+1

Sean Nejad

·

Published

2026-02-19

·

Updated

2026-03-21

·

CVE-2026-32000

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.19 OpenClaw versions 2026.2.17 and earlier
Description OpenClaw versions prior to 2026.2.19 contain a command injection issue in the Lobster extension tool execution. This occurs due to the use of a Windows shell fallback mechanism with shell: true after process creation failures. Attackers can inject shell metacharacters into command arguments, potentially executing arbitrary commands when the subprocess launch fails with EINVAL or ENOENT errors. The issue resides in the extensions/lobster/src/lobster-tool.ts file, where the tool retries subprocess launch with shell: true on Windows for specific errors. The fix removes the shell fallback and uses explicit executable/script argv execution.
Recommendations OpenClaw versions prior to 2026.2.19 should be updated to version 2026.2.19 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-05004
CVE-2026-32000
GHSA-5RP4-CWGH-GVWQ
GHSA-7FCC-CW49-XM78

Affected Products

Blobster
Openclaw