Executive brief
OpenClaw is a development tool used for managing software dependencies. A security flaw allows a malicious project file to trick the system into running unauthorized programs on a developer's computer during the installation process. This could allow an attacker to gain control over the build environment or steal sensitive information if a user opens a compromised workspace.
Technical details
OpenClaw before version 2026.4.29 is vulnerable to an Untrusted Search Path (CWE-426) and path traversal issue within its install helper component. The vulnerability exists because the application allows workspace-level '.env' files to override the 'npm_execpath' configuration variable used during the setup of bundled runtime dependencies. By placing a malicious executable in a specific path and referencing it via a crafted '.env' file, an attacker can achieve arbitrary code execution in the context of the user running the install helper. This requires the victim to open or interact with a malicious workspace. The issue is resolved in version 2026.4.29.
Affected products
- OpenClaw openclaw < 2026.4.29
Timeline
- 2026-05-28: advisory: Original GHSA-24vr-rprv-67rf published
- 2026-06-16: disclosed: NVD publication of CVE-2026-53846
- 2026-06-18: patched: Duplicate advisory withdrawn and patch version confirmed