Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32003

23
FAUCET Score

CVE-2026-32003 details an environment variable injection vulnerability in OpenClaw versions prior to 2026.2.22, specifically within the system.run function. This flaw allows attackers to bypass command allowlist restrictions by manipulating SHELLOPTS and PS4 environment variables, enabling arbitrary shell command execution through bash xtrace expansion. Rated High with a CVSS score of 7.2, a highly privileged attacker can exploit this remotely with low complexity, leading to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor are there any public exploits available, and community discussion remains minimal.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2026.2.22CPE match
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
< 2026.2.22CPE matchmatch criteria
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

7.5HIGH

CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.53%
Probability of exploitation in next 30 days
EPSS Percentile
41.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0053 is in the 19th percentile among its peer group of 5,537 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: openclawFixed in: 2026.2.22

Vendor Advisories (1)

npmGHSA-2fgq-7j6h-9rm4high

OpenClaw has system.run shell-wrapper env injection via SHELLOPTS/PS4 can bypass allowlist intent (RCE)

Mar 3, 2026

References

github.com / openclaw/openclaw/commit/e80c803fa887f9699ad87a9e906ab5c1ff85bd9a
Patch
github.com / openclaw/openclaw/security/advisories/GHSA-2fgq-7j6h-9rm4
Vendor Advisory
vulncheck.com / advisories/openclaw-remote-code-execution-via-shellopts-ps4-environment-injection-in-system-run
Third Party Advisory