CVE-2026-32063Patch(openclaw / openclaw)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generation where attacker-controlled environment values are not validated for CR/LF characters, allowing newline injection to break out of Environment= lines and inject arbitrary systemd directives. An attacker who can influence config.env.vars and trigger service install or restart can execute arbitrary commands with the privileges of the OpenClaw gateway service user.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-11: 1Mentions · 2026-03-15: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-15: 103-1103-15
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-111
Patch1
2026-03-151
Disclosure1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32063 OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generation where attacker-controlled environment value… https://www.cve.org/CVERecord?id=CVE-2026-32063

    Post summary

    A command injection vulnerability (CVE-2026-32063) exists in OpenClaw versions 2026.2.19-2 up to 2026.2.21, allowing attackers to inject commands via environment values during systemd unit file generation.

    10010138
    56.7K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 OpenClaw CVE-2026-32063 just dropped Command injection via newlines in systemd unit generation. If you're running 2026.2.19-2, patch to 2026.2.21 NOW. This is why we validate EVERYTHING. Even newlines can kill you. #infosec #CVE https://t.co/XIh7QEb8ys

    Post summary

    The message announces a new CVE for OpenClaw, describes a command injection vulnerability, and urges users to apply the available patch.

    0001052
    5 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more