High severityNVD Advisory· Published Mar 21, 2026· Updated Mar 23, 2026
OpenClaw < 2026.2.22 - Remote Code Execution via Shell Startup Environment Variable Injection in system.run
CVE-2026-32056
Description
OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attackers to bypass command allowlist protections. Remote attackers can inject malicious startup files such as .bash_profile or .zshenv to achieve arbitrary code execution before allowlist-evaluated commands are executed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openclawnpm | < 2026.2.22 | 2026.2.22 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/openclaw/openclaw/commit/c2c7114ed39a547ab6276e1e933029b9530ee906ghsapatchWEB
- github.com/advisories/GHSA-xgf2-vxv2-rrmgghsaADVISORY
- github.com/openclaw/openclaw/security/advisories/GHSA-xgf2-vxv2-rrmgghsathird-party-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-32056ghsaADVISORY
- www.vulncheck.com/advisories/openclaw-remote-code-execution-via-shell-startup-environment-variable-injection-in-system-runghsathird-party-advisoryWEB
News mentions
0No linked articles in our index yet.