Executive brief
OpenClaw is a development tool that executes commands on a host system with certain protections. The application fails to properly filter dangerous environment variables during these host executions, allowing attackers to inject variables that override critical system configurations such as package managers, container registries, compilers, and TLS settings. An authenticated attacker can exploit this to redirect package downloads, compromise certificate validation, or alter compiler behavior, undermining the security of the host execution environment.
Technical details
OpenClaw's host execution mechanism implements an incomplete blocklist for dangerous environment variables. The vulnerable code fails to sanitize environment variables related to package managers (npm, pip, Go), container registries (Docker), compilers (C, Go), and TLS/certificate validation. An authenticated attacker can request host execution with malicious environment variables (e.g., NPM_REGISTRY, DOCKER_HOST, GOPATH, NODE_EXTRA_CA_CERTS) that override critical system settings. This allows redirection of package downloads to malicious repositories, compromise of container endpoints, or bypass of TLS certificate validation. The vulnerability is classified as CWE-184 (Incomplete List of Disallowed Inputs). The fix, released in version 2026.3.31 (commit eb8de67), adds comprehensive blocking of risky environment variable families to the host-env security policy.
Affected products
- openclaw openclaw <=2026.3.28
Timeline
- 2026-03-31: disclosed: Security advisory GHSA-cg7q-fg22-4g98 published
- 2026-03-31: patched: Fix released in version 2026.3.31 (commit eb8de67)
- 2026-04-28: other: Duplicate advisory GHSA-5mh4-3rv3-fpcf published on OSV
- 2026-05-06: other: Duplicate advisory withdrawn