Incomplete List of Disallowed Inputs in OpenClaw - #VU126835
Published: April 22, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to manipulate trusted OpenClaw runtime behavior.
The vulnerability exists due to incomplete list of disallowed inputs in workspace dotenv loading when processing attacker-controlled workspace environment variables. A local user can set crafted OPENCLAW_ variables to manipulate trusted OpenClaw runtime behavior.
Exploitation requires running OpenClaw from an attacker-controlled workspace before source-update or installer flows.