The OpenClaw software has vulnerabilities that allow attackers to inject malicious environment variables and bypass security controls.
Claims
The OpenClaw software has vulnerabilities that allow attackers to inject malicious environment variables and bypass security controls.
Parent: CybersecurityEntity: OpenClawImpact: negativeDate: Apr 21, 2026Target: The OpenClaw software's security measures
Source posts
๐จ EUVD-2026-23998
๐ Score: 8.5/10 (CVSS v3.1)
๐ฆ Product: OpenClaw, OpenClaw
๐ข Vendor: OpenClaw
๐
Updated: 2026-04-20
๐ OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing environment variable injection. Attackers can place a malicious .env file in a repository or workspace to override runtime co...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23998
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24018
๐ Score: 2.0/10 (CVSS v3.1)
๐ฆ Product: OpenClaw, OpenClaw
๐ข Vendor: OpenClaw
๐
Updated: 2026-04-20
๐ OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to properly enforce proxy, TLS, Docker, and Git TLS controls. Attackers can bypass security controls by overriding environment variab...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24018
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability