Incomplete List of Disallowed Inputs in OpenClaw - #VU125281
Published: April 8, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to incomplete list of disallowed inputs in the exec environment denylist when processing user-controlled build-tool environment variables. A local user can set hostile environment variables to execute arbitrary code.
This issue is scoped to the product's local trust model.