PT-2026-26008 · Openclaw · Openclaw

Tdjackey

+1

·

Published

2026-02-21

·

Updated

2026-03-18

·

CVE-2026-22177

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.21 OpenClaw versions 2026.2.19 and earlier
Description OpenClaw fails to filter dangerous process-control environment variables from configuration environment variables, allowing for startup-time code execution. Attackers can inject variables such as NODE OPTIONS or LD * through configuration to execute arbitrary code within the OpenClaw gateway service runtime context. The issue stems from the collectConfigEnvVars() function accepting unfiltered keys from configuration, which are then merged into the daemon install environment via buildGatewayInstallPlan(). Prior to the fix, startup-control variables were not blocked in this process.
Recommendations OpenClaw versions prior to 2026.2.21 should be updated to version 2026.2.21 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-05062
CVE-2026-22177
GHSA-8FMP-37RC-P5G7

Affected Products

Openclaw