Description
OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing attackers to inject environment variable assignments at the argv level. Attackers can bypass exec preflight handling to manipulate high-risk shell variables like SHELLOPTS and PS4, affecting execution semantics and security controls.
Problem types
CWE-184: Incomplete List of Disallowed Inputs
Product status
2026.2.22 (semver) before 2026.4.12
2026.4.12 (semver)
References
github.com/...enclaw/security/advisories/GHSA-j6c7-3h5x-99g9 (GitHub Security Advisory (GHSA-j6c7-3h5x-99g9))
github.com/...ommit/8f8492d172f4c5b4fd7dd9a47855ed620c8770ab (Patch Commit)
www.vulncheck.com/...vironment-variable-assignment-injection (VulnCheck Advisory: OpenClaw 2026.2.22 < 2026.4.12 - Shell-Wrapper Detection Bypass via Environment Variable Assignment Injection)