Command Injection Vulnerability in OpenClaw by OpenClaw Team
CVE-2026-32052

5.8MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
21 March 2026

What is CVE-2026-32052?

OpenClaw versions before 2026.2.24 are affected by a command injection vulnerability in the system.run shell-wrapper. This flaw enables attackers to execute concealed commands by injecting positional argv carriers following inline shell payloads. By crafting misleading approval texts, attackers can run arbitrary commands while evading validation checks that ensure proper display context, leading to potential exploitation of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

OpenClaw 0 < 2026.2.24

OpenClaw 2026.2.24

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tdjackey
.