Untrusted search path in OpenClaw - #VU132742
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to execute an unintended executable.
The vulnerability exists due to improper control of executable selection in the skill install helper when processing a workspace .env file during skill install flows. A local user can place a crafted .env file in a repository to execute an unintended executable.
Only installations with the affected feature enabled and reachable are vulnerable.