CVE-2026-32052
OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidden commands by injecting positional argv carriers after inline shell payloads. Attackers can craft misleading approval text while executing arbitrary commands through trailing positional arguments that bypass display context validation.
Vendor
Product
CWE
Yayın Tarihi
2026-03-21 01:17:08
Güncelleme
2026-03-23 17:07:49
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/openclaw/openclaw/commit/0f0a680d3df81739ea5088a2f88e65f938b7936b
https://github.com/openclaw/openclaw/commit/55cf92578d266987e390c4bf688196af98eac748
https://github.com/openclaw/openclaw/security/advisories/GHSA-6rcp-vxwf-3mfp
https://www.vulncheck.com/advisories/openclaw-hidden-command-execution-via-shell-wrapper-positional-argv-carriers