Description
OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influence Python runtime selection through CLOUDSDK_PYTHON during Gmail setup gcloud execution. Attackers with repository access can manipulate the CLOUDSDK_PYTHON variable to execute setup through unintended local Python paths, potentially enabling arbitrary code execution.
Problem types
Product status
Any version before 2026.5.2
2026.5.2 (semver)
Credits
侯海飞 (@feynman-hou)
References
github.com/...enclaw/security/advisories/GHSA-fq9j-vw4w-fr6v (GitHub Security Advisory (GHSA-fq9j-vw4w-fr6v))
www.vulncheck.com/...ia-cloudsdk-python-environment-variable (VulnCheck Advisory: OpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON Environment Variable)