CVE-2026-32003: OpenClaw has system.run shell-wrapper env injection via SHELLOPTS/PS4 can bypass allowlist intent (RCE)
(updated )
system.run allowed SHELLOPTS + PS4 environment injection to trigger command substitution during bash -lc xtrace expansion before the allowlisted command body executed.
References
- github.com/advisories/GHSA-2fgq-7j6h-9rm4
- github.com/openclaw/openclaw
- github.com/openclaw/openclaw/commit/e80c803fa887f9699ad87a9e906ab5c1ff85bd9a
- github.com/openclaw/openclaw/security/advisories/GHSA-2fgq-7j6h-9rm4
- nvd.nist.gov/vuln/detail/CVE-2026-32003
- www.vulncheck.com/advisories/openclaw-remote-code-execution-via-shellopts-ps4-environment-injection-in-system-run
Code Behaviors & Features
Detect and mitigate CVE-2026-32003 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →