OS Command Injection in OpenClaw - CVE-2026-22177
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary commands.
The vulnerability exists due to command injection in the host exec feature when inheriting environment variables that influence interpreters, shells, or build tools. A local user can control environment variables to execute arbitrary commands.
The issue is scoped to the product's user-controlled local assistant trust model.