PT-2026-32066 · Npm · Openclaw
Publicado
2026-04-01
·
Atualizado
2026-04-01
CVSS v3.1
9.6
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Summary
OpenClaw loaded the current working directory
.env before trusted state-dir configuration, allowing untrusted workspace state to inject host environment values.Impact
A repository or workspace containing a malicious
.env file could override runtime configuration and security-sensitive environment settings when OpenClaw started there.Affected Component
src/infra/dotenv.ts, src/cli/dotenv.tsFixed Versions
- Affected:
<= 2026.3.24 - Patched:
>= 2026.3.28 - Latest stable
2026.3.28contains the fix.
Fix
Fixed by commit
6a79324802 (Filter untrusted CWD .env entries before OpenClaw startup).Correção
Untrusted Search Path
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openclaw