Openclaw cli: OpenClaw has system.run shell-wrapper env injection via SHELLOPTS/PS4 can bypass allowlist intent (RCE) (CVE-2026-32003)
Description
OpenClaw CLI versions up to 2026.2.21-2 have a vulnerability in the system.run function where environment variables SHELLOPTS and PS4 can be injected to bypass the allowlist intent, enabling command execution outside the intended scope. This occurs due to insufficient sanitization of these environment variables, which are evaluated by bash during xtrace expansion. The issue is rated medium severity because exploitation requires the ability to invoke system.run with request-scoped environment variables, which is limited to trusted callers under OpenClaw's security model. A fix is planned in version 2026.2.22 that blocks these environment variables and restricts allowed environment overrides.
CVSS v3.1
Score 6.6medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The OpenClaw CLI system.run function allowed injection of the SHELLOPTS and PS4 environment variables, which are evaluated by bash during xtrace expansion when running shell wrappers with -c or -lc options. This bypasses the allowlist mechanism intended to restrict command execution, enabling attackers who can invoke system.run with request-scoped environment variables to execute arbitrary shell commands outside the allowlisted command body. The root cause is incomplete environment sanitization that blocked common startup-file vectors but did not block SHELLOPTS and PS4. The fix involves blocking these variables and limiting environment overrides to a strict allowlist.
Potential Impact
An attacker with the ability to invoke system.run with request-scoped environment variables can execute arbitrary shell commands beyond the intended allowlist restrictions. However, exploitation requires existing privileges to call system.run, which under OpenClaw's trust model means the attacker is already a trusted operator. Therefore, the vulnerability does not cross a separate trust boundary and is rated medium severity.
Mitigation Recommendations
A fix is available and planned for release in OpenClaw CLI version 2026.2.22. The patch blocks the SHELLOPTS and PS4 environment variables in the host execution environment sanitizers and restricts environment overrides to an explicit allowlist of safe variables. Users should upgrade to version 2026.2.22 once it is published. Until then, be aware that the vulnerability requires the ability to invoke system.run with environment overrides.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-32003
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6ac245db12601ec6a31680b9
Added to database: 10/04/2026, 12:26:03 UTC
Last enriched: 10/04/2026, 13:22:24 UTC
Last updated: 10/04/2026, 16:08:37 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.