External Control of System or Configuration Setting in OpenClaw - #VU132743
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to execute unintended local code.
The vulnerability exists due to improper control of environment variables in the Gmail setup gcloud execution feature when processing a repository workspace .env file. A remote user can supply a crafted workspace .env that sets CLOUDSDK_PYTHON to execute unintended local code.
Exploitation requires the affected feature to be enabled and reachable, and a trusted operator to open the repository.