Description
OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypass the shared host environment policy through inconsistent sanitization paths. Attackers can supply blocked or malformed override keys that slip through inconsistent validation to execute arbitrary code with unintended environment variables.
Problem types
CWE-15: External Control of System or Configuration Setting
Product status
Any version before 2026.3.22
2026.3.22 (semver)
Credits
Peng Zhou (@zpbrent)
References
github.com/...enclaw/security/advisories/GHSA-39pp-xp36-q6mg (GitHub Security Advisory (GHSA-39pp-xp36-q6mg))
github.com/...ommit/630f1479c44f78484dfa21bb407cbe6f171dac87 (Patch Commit #1)
github.com/...ommit/7abfff756d6c68d17e21d1657bbacbaec86de232 (Patch Commit #2)
www.vulncheck.com/...de-bypass-via-inconsistent-sanitization (VulnCheck Advisory: OpenClaw < 2026.3.22 - Environment Variable Override Bypass via Inconsistent Sanitization)