CVE-2026-32052
MEDIUMOpenClaw < 2026.2.24 - Hidden Command Execution via Shell-Wrapper Positional argv Carriers
Title source: cnaDescription
OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidden commands by injecting positional argv carriers after inline shell payloads. Attackers can craft misleading approval text while executing arbitrary commands through trailing positional arguments that bypass display context validation.
References (4)
Core 4
Core References
Third Party Advisory third-party-advisory
GitHub Security Advisory (GHSA-6rcp-vxwf-3mfp)
https://github.com/openclaw/openclaw/security/advisories/GHSA-6rcp-vxwf-3mfp
Patch patch
Patch Commit #1
https://github.com/openclaw/openclaw/commit/0f0a680d3df81739ea5088a2f88e65f938b7936b
Patch patch
Patch Commit #2
https://github.com/openclaw/openclaw/commit/55cf92578d266987e390c4bf688196af98eac748
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.2.24 - Hidden Command Execution via Shell-Wrapper Positional argv Carriers
https://www.vulncheck.com/advisories/openclaw-hidden-command-execution-via-shell-wrapper-positional-argv-carriers
Scores
CVSS v3
6.4
EPSS
0.0091
EPSS Percentile
55.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-436
CWE-77
Status
published
Products (4)
npm/openclaw
0 - 2026.2.24npm
OpenClaw/OpenClaw
< 2026.2.24
openclaw/openclaw
< 2026.2.24
OpenClaw/OpenClaw
2026.2.24
Published
Mar 21, 2026
Tracked Since
Mar 21, 2026