Junglewise Threat Intelligence

OpenClaw path traversal in install helper via npm_execpath override

Severity: high · CVSS 7.1 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a development tool used for managing software dependencies. A security flaw allows a malicious project file to trick the system into running unauthorized programs on a developer's computer during the installation process. This could allow an attacker to gain control over the build environment or steal sensitive information if a user opens a compromised workspace.

Technical details

OpenClaw before version 2026.4.29 is vulnerable to an Untrusted Search Path (CWE-426) and path traversal issue within its install helper component. The vulnerability exists because the application allows workspace-level '.env' files to override the 'npm_execpath' configuration variable used during the setup of bundled runtime dependencies. By placing a malicious executable in a specific path and referencing it via a crafted '.env' file, an attacker can achieve arbitrary code execution in the context of the user running the install helper. This requires the victim to open or interact with a malicious workspace. The issue is resolved in version 2026.4.29.

Affected products

  • OpenClaw openclaw < 2026.4.29

Timeline

  • 2026-05-28: advisory: Original GHSA-24vr-rprv-67rf published
  • 2026-06-16: disclosed: NVD publication of CVE-2026-53846
  • 2026-06-18: patched: Duplicate advisory withdrawn and patch version confirmed

References

Related threats