External Control of System or Configuration Setting in OpenClaw - CVE-2026-32056
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to external control of system configuration settings in the system.run shell execution path when processing attacker-supplied environment variables for shell startup. A remote attacker can supply crafted HOME or ZDOTDIR values to execute arbitrary code.
Exploitation relies on shell startup files being processed before the allowlist-evaluated command body.