Executive brief
Crabbox, a tool used for managing remote command execution and development environments, contains a security flaw in how it handles local configuration files. An attacker who can convince a user to run Crabbox within a malicious or compromised code repository can automatically steal sensitive local information, such as API tokens, cloud credentials, and security keys. This occurs because the tool can be tricked into forwarding all of the user's private environment variables to a remote server controlled by the attacker.
Technical details
Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability (CWE-94/CWE-200) due to improper validation of wildcard patterns in the environment allowlist. The root cause is in the `envAllowed()` function, which accepted a bare wildcard ('*') as a valid prefix. Because every environment variable name matches an empty prefix, this configuration causes the tool to serialize and forward the entire local `os.Environ()` to the remote command environment. An attacker can exploit this by committing a malicious `.crabbox.yaml` file to a repository; when an operator runs Crabbox within that repository, all local secrets are leaked to the remote lease. This was fixed in v0.12.0 by rejecting empty-prefix wildcards.
Affected products
- openclaw Crabbox < 0.12.0
Timeline
- 2026-05-11: patched: Fix merged in pull request 78
- 2026-05-12: advisory: Release v0.12.0 published
- 2026-05-14: disclosed: CVE-2026-8634 published