CVE-2026-32032 | OpenClaw up to 2026.2.21 Environment Variable SHELL untrusted search path (GHSA-f8mp-vj46-cq8v / WID-SEC-2026-0472)
A vulnerability was found in OpenClaw up to 2026.2.21 and classified as problematic. This vulnerability affects unknown code of the component Environment Variable Handler. Such manipulation of the argument SHELL leads to untrusted search path.
This vulnerability is uniquely identified as CVE-2026-32032. Local access is required to approach this attack. No exploit exists.
It is suggested to upgrade the affected component.