Executive brief
OpenClaw, a development and execution platform, contains a security flaw in how it handles system commands. An attacker with low-level access can bypass security filters by injecting specific environment variables related to the Rust programming language's toolchain. This could allow an unauthorized user to execute arbitrary commands or gain higher-level permissions on the host system, potentially leading to a full system compromise or data theft.
Technical details
OpenClaw versions prior to 2026.6.6 suffer from an environment variable filtering vulnerability (CWE-184, CWE-94) within the host execution (host exec) feature. The root cause is a failure to properly sanitize or block 'rustup' startup variables, which can be manipulated to influence the execution environment. An attacker with network access and low-level privileges can provide malicious input paths or caller data to achieve code execution or privilege escalation. The vulnerability is exploited by injecting environment variables that the filtering mechanism fails to catch, allowing the attacker to control the behavior of the underlying host process. Users are advised to upgrade to version 2026.6.6 or later.
Affected products
- OpenClaw OpenClaw < 2026.6.6
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-16: advisory: VulnCheck advisory published
- 2026-07-17: disclosed: NVD publication date