CVE-2026-32000
MEDIUM
openclaw
NVD
CVSS Score
6.3
Severity
MEDIUM
Published
Mar 19, 2026
Vendor
openclaw
Description
OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallback with shell: true after spawn failures. Attackers can inject shell metacharacters in command arguments to execute arbitrary commands when subprocess launch fails with EINVAL or ENOENT errors.