PT-2026-26734 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-03

·

Updated

2026-03-21

·

CVE-2026-32052

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.24
Description The software contains a command injection issue in the system.run shell-wrapper. This allows attackers to execute hidden commands by injecting positional argv carriers after inline shell payloads. Attackers can craft misleading approval text while executing arbitrary commands through trailing positional arguments, bypassing display context validation.
Recommendations Update OpenClaw to version 2026.2.24 or later.

Fix

Command Injection

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32052
GHSA-6RCP-VXWF-3MFP
GHSA-W6F4-3V35-QJHJ

Affected Products

Openclaw