
CVE-2026-32003 OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the http://system.run function that allows attackers to bypass command allowl… https://www.cve.org/CVERecord?id=CVE-2026-32003
Post summary
The post announces that OpenClaw versions before 2026.2.22 are vulnerable to environment variable injection via the http://system.run function, allowing command bypass.
