HIGH
OpenClaw 2026.2.19-2 < 2026.2.21 - Command Injection via Newline in systemd Unit Generation
Published Mar 11, 2026
8.6
HIGHCVSS 4.0
EPSS 1.32%
Description
OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generation where attacker-controlled environment values are not validated for CR/LF characters, allowing newline injection to break out of Environment= lines and inject arbitrary systemd directives. An attacker who can influence config.env.vars and trigger service install or restart can execute arbitrary commands with the privileges of the OpenClaw gateway service user.
Affected products
-
Affected
- ≥ 2026.2.19-2, < 2026.2.21
Unaffected
- 2026.2.21
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.2.21
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.2.21 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-11156 Advisory
- https://github.com/advisories/GHSA-vffc-f7r7-rx2w Advisory
- https://github.com/openclaw/openclaw/commit/61f646c41fb43cd87ed48f9125b4718a30d38e84 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-vffc-f7r7-rx2w exploitvendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-32063
- https://www.vulncheck.com/advisories/openclaw-command-injection-via-newline-in-systemd-unit-generation third-party-advisoryBroken Link
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-11156 | Advisory | |
| https://github.com/advisories/GHSA-vffc-f7r7-rx2w | Advisory | |
| https://github.com/openclaw/openclaw/commit/61f646c41fb43cd87ed48f9125b4718a30d38e84 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-vffc-f7r7-rx2w | exploitvendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-32063 | ||
| https://www.vulncheck.com/advisories/openclaw-command-injection-via-newline-in-systemd-unit-generation | third-party-advisoryBroken Link |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 11, 2026
Updated Mar 11, 2026
Reserved Mar 10, 2026
Link CVE-2026-32063
CISA Vulnrichment
Updated Mar 11, 2026
Red Hat
No data
GitHub
Link GHSA-VFFC-F7R7-RX2W