top of page
perceptive_background_267k.jpg

OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environme…

Published:

27 april 2026 om 22:00:00

Alert date:

28 april 2026 om 20:08:59

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools

OpenClaw versions before 2026.3.24 contain a critical environment variable injection vulnerability in the CLI backend runner. Attackers can exploit this flaw by crafting malicious workspace configuration files to inject arbitrary environment variables into the backend process. This vulnerability enables code execution and sensitive data exposure through the workspace configuration mechanism. The vulnerability affects the CLI backend runner component specifically and has been addressed in version 2026.3.24.

Technical details

Mitigation steps:

Affected products:

OpenClaw

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page