


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control variables. Atta…
Published:
4 May 2026 at 22:00:00
Alert date:
5 May 2026 at 20:13:49
Source:
nvd.nist.gov
Enterprise Applications, Supply Chain & Dependencies
OpenClaw before version 2026.4.9 contains an environment variable injection vulnerability that allows attackers to manipulate runtime-control variables through malicious workspace .env files. The vulnerability enables attackers to inject variables that can affect critical application components including update sources, gateway URLs, ClawHub resolution, and browser executable paths. This can lead to compromise of application behavior and potentially allow attackers to redirect the application to malicious sources or execute arbitrary code through browser path manipulation. The vulnerability has been assigned CVE-2026-43531 and affects all versions of OpenClaw prior to 2026.4.9.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-43531
https://github.com/openclaw/openclaw/commit/dbfcef319618158fa40b31cdac386ea34c392c0c
https://github.com/openclaw/openclaw/security/advisories/GHSA-7wv4-cc7p-jhxc
https://www.vulncheck.com/advisories/openclaw-environment-variable-injection-via-workspace-env-file
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
