Incomplete List of Disallowed Inputs in OpenClaw - #VU125281

 

Incomplete List of Disallowed Inputs in OpenClaw - #VU125281

Published: April 8, 2026


Vulnerability identifier: #VU125281
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-184
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to incomplete list of disallowed inputs in the exec environment denylist when processing user-controlled build-tool environment variables. A local user can set hostile environment variables to execute arbitrary code.

This issue is scoped to the product's local trust model.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.4.8

External References

Related Security Bulletins