Junglewise Threat Intelligence

CVE-2026-62199: OpenClaw OS command injection via environment variable filtering

CVE-2026-62199 · Severity: high · CVSS 8.8 · Published 2026-07-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing host execution environments, contains a security flaw in how it filters environment variables. An attacker with low-level access can bypass security restrictions by providing specially crafted variables that influence how the system starts up. This could allow an unauthorized user to execute commands or perform actions they are not permitted to do, potentially leading to a full system compromise or data theft.

Technical details

OpenClaw versions prior to 2026.6.6 are vulnerable to an OS command injection and input validation flaw (CWE-78, CWE-184). The vulnerability exists in the host execution environment filtering mechanism, which fails to properly sanitize or block interpreter startup variables. A remote attacker with low privileges can provide crafted environment variables via a reachable input path to execute arbitrary actions or persist unauthorized changes. This bypasses the intended authorization boundaries of the host execution environment. The issue is resolved in version 2026.6.6; users are advised to upgrade or restrict the affected feature to trusted operators.

Affected products

  • OpenClaw OpenClaw < 2026.6.6

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-13: disclosed: NVD publication date

References

Related threats