CVE-2026-32052 identifies a command injection vulnerability in OpenClaw versions prior to 2026.2.24, specifically within its `system.run` shell-wrapper. This flaw allows authenticated attackers to execute arbitrary, hidden commands by injecting positional arguments after inline shell payloads, bypassing display context validation. Rated Medium with a CVSS score of 6.4, exploitation requires low privileges and user interaction over the network, but has high attack complexity, potentially leading to high impact on system integrity and availability. There is currently no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB, and community discussion and media coverage for this vulnerability are absent.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.2.24CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.2.24CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.