Junglewise Threat Intelligence

OpenClaw insufficient environment variable sanitization in host sanitizer

Severity: high · CVSS 8.1 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a development tool platform, contains a security flaw in how it handles environment configuration files. An attacker with the ability to modify workspace settings or environment files can bypass security filters to inject malicious Node.js control variables. This could allow an attacker to manipulate background processes or redirect data output, potentially leading to unauthorized data access or system compromise.

Technical details

OpenClaw versions prior to 2026.5.26 are vulnerable to an incomplete list of disallowed inputs (CWE-184) within the host environment sanitizer. The sanitizer fails to block specific Node.js control variables, which can be injected through workspace .env files, tool environment overrides, or skill environment blocks. An authenticated attacker with low privileges can exploit this to influence child processes or manipulate coverage output paths when those processes are launched. The vulnerability is remediated in version 2026.5.26.

Affected products

  • OpenClaw openclaw < 2026.5.26

Timeline

  • 2026-05-28: advisory: Original advisory GHSA-ccwh-wwpp-6wg5 published
  • 2026-06-16: disclosed: CVE-2026-53864 published
  • 2026-06-18: patched: Duplicate advisory GHSA-vr6h-vxqj-3pjx withdrawn in favor of GHSA-ccwh-wwpp-6wg5

References

Related threats