CVE-2026-32063 is a high-severity command injection vulnerability (CVSS 7.8) affecting OpenClaw versions prior to 2026.2.21. This flaw allows a local attacker with low privileges to inject arbitrary systemd directives by manipulating environment variables, leading to arbitrary command execution with the OpenClaw gateway service user's privileges. The vulnerability stems from insufficient validation of CR/LF characters in environment values during systemd unit file generation, enabling newline injection. Currently, there is no evidence of active exploitation, nor are public exploit codes or significant community discussion available for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2026.2.19-2, < 2026.2.21CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.2.21CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.