Incomplete List of Disallowed Inputs in OpenClaw - #VU125285
Published: April 8, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to redirect Git operations.
The vulnerability exists due to an incomplete list of disallowed inputs in the exec environment denylist when executing host commands. A local user can set git plumbing environment variables to redirect Git operations.
This issue is scoped to the product's local assistant trust model and does not assume a multi-tenant service boundary.