Protection Mechanism Failure in OpenClaw - #VU128582
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to influence downstream execution or network behavior.
The vulnerability exists due to improper restriction of dangerous environment variables in exec environment policy when processing operator-supplied environment overrides. A remote user can supply crafted interpreter startup variables to influence downstream execution or network behavior.