PT-2026-26008 · Openclaw · Openclaw

Tdjackey

+1

·

Publicado

2026-02-21

·

Atualizado

2026-03-18

·

CVE-2026-22177

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.21 OpenClaw versions 2026.2.19 and earlier
Description OpenClaw fails to filter dangerous process-control environment variables from configuration environment variables, allowing for startup-time code execution. Attackers can inject variables such as NODE OPTIONS or LD * through configuration to execute arbitrary code within the OpenClaw gateway service runtime context. The issue stems from the collectConfigEnvVars() function accepting unfiltered keys from configuration, which are then merged into the daemon install environment via buildGatewayInstallPlan(). Prior to the fix, startup-control variables were not blocked in this process.
Recommendations OpenClaw versions prior to 2026.2.21 should be updated to version 2026.2.21 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05062
CVE-2026-22177
GHSA-8FMP-37RC-P5G7

Produtos afetados

Openclaw