HIGH
OpenClaw < 2026.2.22 - Remote Code Execution via SHELLOPTS/PS4 Environment Injection in system.run
Published Mar 19, 2026
7.5
HIGHCVSS 4.0
EPSS 0.81%
Description
OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function that allows attackers to bypass command allowlist restrictions via SHELLOPTS and PS4 environment variables. An attacker who can invoke system.run with request-scoped environment variables can execute arbitrary shell commands outside the intended allowlisted command body through bash xtrace expansion.
Affected products
-
- Version 0StatusaffectedConstraints<2026.2.22
- Version 2026.2.22StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.2.22
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.2.22 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://github.com/advisories/GHSA-2fgq-7j6h-9rm4 Advisory
- https://github.com/openclaw/openclaw/commit/e80c803fa887f9699ad87a9e906ab5c1ff85bd9a patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-2fgq-7j6h-9rm4 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-32003
- https://www.vulncheck.com/advisories/openclaw-remote-code-execution-via-shellopts-ps4-environment-injection-in-system-run third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-2fgq-7j6h-9rm4 | Advisory | |
| https://github.com/openclaw/openclaw/commit/e80c803fa887f9699ad87a9e906ab5c1ff85bd9a | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-2fgq-7j6h-9rm4 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-32003 | ||
| https://www.vulncheck.com/advisories/openclaw-remote-code-execution-via-shellopts-ps4-environment-injection-in-system-run | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 19, 2026
Updated Jun 23, 2026
Reserved Mar 10, 2026
Link CVE-2026-32003
CISA Vulnrichment
GHSA-2FGQ-7J6H-9RM4 Updated Mar 21, 2026