Junglewise Threat Intelligence

CVE-2026-43584: OpenClaw exec environment denylist bypass via interpreter startup variables

CVE-2026-43584 · Severity: low · CVSS 3.1 · Published 2026-04-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a runtime environment that executes untrusted code while enforcing security policies. The environment variable denylist was incomplete, missing high-risk startup variables (VIMINIT, EXINIT, LUA_INIT, HOSTALIASES) that control interpreter behavior. An operator could exploit this to influence downstream execution or network behavior, potentially gaining unauthorized access or modifying system operations.

Technical details

OpenClaw's exec environment security policy uses a denylist of environment variables to prevent operator-supplied overrides from compromising execution safety. The vulnerability is an incomplete denylist (CWE-184: Incomplete List of Disallowed Inputs) that missed high-risk interpreter startup variables such as VIMINIT, EXINIT, LUA_INIT, and HOSTALIASES. An authenticated operator can supply these variables to influence downstream code execution or network behavior. Attack requires operator access to supply environment variables at execution time. The fix expands the denylist in openclaw 2026.4.10 and later to cover these and related high-risk variables.

Affected products

  • OpenClaw OpenClaw < 2026.4.10

Timeline

  • 2026-04-17: disclosed
  • 2026-04-17: patched: Fixed in v2026.4.10 and later

References

Related threats