PT-2026-26008 · Openclaw · Openclaw

·

CVE-2026-22177

·

Published

2026-02-21

·

Updated

2026-04-09

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.21 OpenClaw versions 2026.2.19 and earlier
Description OpenClaw fails to filter dangerous process-control environment variables from configuration environment variables, allowing for startup-time code execution. Attackers can inject variables such as NODE OPTIONS or LD * through configuration to execute arbitrary code within the OpenClaw gateway service runtime context. The issue stems from the collectConfigEnvVars() function accepting unfiltered keys from configuration, which are then merged into the daemon install environment via buildGatewayInstallPlan(). Prior to the fix, startup-control variables were not blocked in this process.
Recommendations OpenClaw versions prior to 2026.2.21 should be updated to version 2026.2.21 or later.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05062
CVE-2026-22177
GHSA-8FMP-37RC-P5G7
GHSA-W9J9-W4CP-6WGR

Affected Products

Openclaw