Executive brief
OpenClaw is an AI automation tool used to execute tasks across operating systems and platforms. A vulnerability in versions before 2026.4.29 allows a workspace's .env file to override which package manager executable is used when installing dependencies. An attacker with workspace access could substitute their own malicious package manager, leading to arbitrary code execution during the build or dependency installation process.
Technical details
This vulnerability is classified as an untrusted search path issue (CWE-426) affecting OpenClaw's install helper functionality. The vulnerability occurs when the npm_execpath configuration can be overridden by workspace-level .env files, allowing an attacker to specify a malicious or untrusted package-manager executable. The attack requires local access to a workspace and user interaction (a trusted operator must open or work with the repository), but no special authentication. When triggered, the attacker can execute arbitrary code with the privileges of the operator running the install helper. The fix is available in version 2026.4.29 and later. Until patching, the recommended mitigation is to only install bundled runtime dependencies from trusted workspaces.
Affected products
- OpenClaw openclaw < 2026.4.29
Timeline
- 2026-06-18: disclosed: GHSA-24vr-rprv-67rf published
- 2026-04-29: patched: Version 2026.4.29 released with fix