LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-32052

openclaw · openclaw

Published
CVSS6.4
Severitymedium
WeaknessCWE-436
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H

Description

OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidden commands by injecting positional argv carriers after inline shell payloads. Attackers can craft misleading approval text while executing arbitrary commands through trailing positional arguments that bypass display context validation.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32052

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32052.