Executive brief
OpenClaw is a platform for managing automated tools and developer workflows. A security flaw in its environment variable sanitizer allows untrusted configuration files (like .env files) to inject sensitive Node.js control variables. This could allow an attacker to manipulate how background processes run, potentially leading to unauthorized data access or system interference.
Technical details
A vulnerability exists in OpenClaw's environment variable sanitization logic (CWE-184) where two Node.js control variables are not properly filtered. An attacker with the ability to provide lower-trust environment inputs—such as through a workspace .env file, tool environment override, or skill environment block—can pass these variables through the shared sanitizer. When the affected feature is enabled, these variables can influence subsequent Node.js child processes or coverage output paths. This requires low privileges and is reachable via the network. The issue is patched in version 2026.5.26.
Affected products
- openclaw openclaw <= 2026.5.22
Timeline
- 2026-05-28: disclosed
- 2026-06-18: advisory: GitHub Advisory published
- 2026-05-26: patched
References
- https://api.github.com/users/nayakchinmohan
- https://github.com/nayakchinmohan
- https://api.github.com/users/nayakchinmohan/gists%7B/gist_id%7D
- https://api.github.com/users/nayakchinmohan/repos
- https://avatars.githubusercontent.com/u/6557536?v=4
- https://api.github.com/users/nayakchinmohan/events%7B/privacy%7D