Skip to main content
EPSS 0.8%top 45%

Openclaw cli: OpenClaw has system.run shell-wrapper env injection via SHELLOPTS/PS4 can bypass allowlist intent (RCE) (CVE-2026-32003)

0
Medium
Published: 08/13/2026 (08/13/2026, 17:21:32 UTC)
Source: GCVE Database
Product: openclaw-cli

Description

OpenClaw CLI versions up to 2026.2.21-2 have a vulnerability in the system.run function where environment variables SHELLOPTS and PS4 can be injected to bypass the allowlist intent, enabling command execution outside the intended scope. This occurs due to insufficient sanitization of these environment variables, which are evaluated by bash during xtrace expansion. The issue is rated medium severity because exploitation requires the ability to invoke system.run with request-scoped environment variables, which is limited to trusted callers under OpenClaw's security model. A fix is planned in version 2026.2.22 that blocks these environment variables and restricts allowed environment overrides.

CVSS v3.1

Score 6.6medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected software

Homebrewmore threats →ghsa
openclaw-cli
pkg:brew/openclaw-cli
Affected versions
<2026.7.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/04/2026, 13:22:24 UTC

Technical Analysis

The OpenClaw CLI system.run function allowed injection of the SHELLOPTS and PS4 environment variables, which are evaluated by bash during xtrace expansion when running shell wrappers with -c or -lc options. This bypasses the allowlist mechanism intended to restrict command execution, enabling attackers who can invoke system.run with request-scoped environment variables to execute arbitrary shell commands outside the allowlisted command body. The root cause is incomplete environment sanitization that blocked common startup-file vectors but did not block SHELLOPTS and PS4. The fix involves blocking these variables and limiting environment overrides to a strict allowlist.

Potential Impact

An attacker with the ability to invoke system.run with request-scoped environment variables can execute arbitrary shell commands beyond the intended allowlist restrictions. However, exploitation requires existing privileges to call system.run, which under OpenClaw's trust model means the attacker is already a trusted operator. Therefore, the vulnerability does not cross a separate trust boundary and is rated medium severity.

Mitigation Recommendations

A fix is available and planned for release in OpenClaw CLI version 2026.2.22. The patch blocks the SHELLOPTS and PS4 environment variables in the host execution environment sanitizers and restricts environment overrides to an explicit allowlist of safe variables. Users should upgrade to version 2026.2.22 once it is published. Until then, be aware that the vulnerability requires the ability to invoke system.run with environment overrides.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-openclaw-cli-CVE-2026-32003
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
3.1

Threat ID: 6ac245db12601ec6a31680b9

Added to database: 10/04/2026, 12:26:03 UTC

Last enriched: 10/04/2026, 13:22:24 UTC

Last updated: 10/04/2026, 16:08:37 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses