


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control variables. Atta…
Published:
4 May 2026 at 22:00:00
Alert date:
5 May 2026 at 13:07:56
Source:
nvd.nist.gov
Enterprise Applications, Supply Chain & Dependencies
OpenClaw versions before 2026.4.9 contain an environment variable injection vulnerability that allows attackers to exploit malicious workspace .env files. The vulnerability enables injection of variables that control critical runtime parameters including update sources, gateway URLs, ClawHub resolution, and browser executable paths. This can lead to complete compromise of application behavior and potential system takeover. The vulnerability affects the core configuration mechanism of the OpenClaw application through malicious environment file manipulation.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-43531
https://github.com/openclaw/openclaw/commit/dbfcef319618158fa40b31cdac386ea34c392c0c
https://github.com/openclaw/openclaw/security/advisories/GHSA-7wv4-cc7p-jhxc
https://www.vulncheck.com/advisories/openclaw-environment-variable-injection-via-workspace-env-file
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
