Untrusted search path in OpenClaw - #VU132747
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to execute an unintended local package-manager executable.
The vulnerability exists due to improper control of executable path in the bundled runtime dependency install helper when processing a workspace .env file in a repository opened by a trusted operator. A remote user can supply a repository containing a crafted workspace .env file to execute an unintended local package-manager executable.
Only configurations where the affected feature is enabled and reachable are vulnerable.