Executive brief
OpenClaw is a sandboxing library that uses SSH to safely execute untrusted code. The SSH-based sandbox backends were passing the entire unsanitized process environment to child processes, which could leak sensitive information like API keys and credentials. While local exploitation requires direct SSH access, the vulnerability could expose secrets in multi-tenant or shared environments.
Technical details
The vulnerability is an information disclosure issue (CWE-212) in OpenClaw's SSH sandbox backends. The root cause is that unsanitized process.env variables are passed directly to SSH child processes without filtering. The attack vector is local, requiring a user with SSH access to the sandbox host or a non-default SSH environment forwarding configuration on remote systems. An attacker can read sensitive environment variables set by the application or its parent processes, potentially obtaining API keys, credentials, or other secrets. The issue is fixed in version 2026.3.31 and later, with the fix applied on 2026-03-30 (commit cfe1445).
Affected products
- OpenClaw OpenClaw <=2026.3.28
Timeline
- 2026-04-02: disclosed: GHSA-j9pv-rrcj-6pfx published
- 2026-03-30: patched: Fix committed and released in v2026.3.31