CVE-2026-32056 | OpenClaw up to 2026.2.21 Environment Variable HOME/ZDOTDIR os command injection (GHSA-xgf2-vxv2-rrmg)
A vulnerability was found in OpenClaw up to 2026.2.21 and classified as critical. The affected element is an unknown function of the component Environment Variable Handler. Such manipulation of the argument HOME/ZDOTDIR leads to os command injection.
This vulnerability is referenced as CVE-2026-32056. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.