PT-2026-26738 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-03
·
Updated
2026-03-21
·
CVE-2026-32056
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.22
Description
OpenClaw does not properly sanitize shell startup environment variables
HOME and ZDOTDIR within the system.run function. This allows attackers to bypass command allowlist protections. By injecting malicious startup files, such as .bash profile or .zshenv, attackers can achieve arbitrary code execution before allowlist-evaluated commands are executed.Recommendations
Update OpenClaw to version 2026.2.22 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw