PT-2026-27239 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-32907

CVSS v3.1

7.8

High

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
OpenClaw before 2026.2.19 contains a local command injection vulnerability in Windows scheduled task script generation that allows attackers to execute arbitrary commands by injecting cmd metacharacters into unsafe gateway.cmd arguments. Attackers with control over service script generation values can inject unescaped metacharacters or expansion-sensitive characters to achieve unintended command execution in the scheduled task context.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-32907

Affected Products

Openclaw