Junglewise Threat Intelligence

OpenClaw insufficient environment variable denylist in exec policy

Severity: high · CVSS 8.8 · Published 2026-05-06

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing execution environments, contains a security flaw in how it filters system settings. An attacker can bypass security restrictions by providing specific environment variables that influence how the system starts up or connects to networks. This could allow an unauthorized user to alter the behavior of the software or gain control over downstream execution processes.

Technical details

OpenClaw versions prior to 2026.4.10 suffer from an incomplete denylist (CWE-184) in its execution environment policy. The vulnerability allows an attacker with low privileges to supply environment variable overrides for high-risk interpreter startup variables, such as VIMINIT, EXINIT, LUA_INIT, and HOSTALIASES. By manipulating these variables, an attacker can influence downstream execution behavior or redirect network connectivity. The issue is reachable over the network without user interaction. A fix was introduced in version 2026.4.10 which expands the host environment security policy denylist to include these high-risk variables.

Affected products

  • OpenClaw openclaw < 2026.4.10

Timeline

  • 2026-04-16: advisory: Original GHSA-vfp4-8x56-j7c5 published
  • 2026-05-06: disclosed: CVE-2026-43584 published to NVD
  • 2026-05-11: patched: Duplicate advisory withdrawn and fix confirmed in 2026.4.10

References

Related threats