PT-2026-26008 · Openclaw · Openclaw
Tdjackey
+1
·
Published
2026-02-21
·
Updated
2026-03-18
·
CVE-2026-22177
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.21
OpenClaw versions 2026.2.19 and earlier
Description
OpenClaw fails to filter dangerous process-control environment variables from configuration environment variables, allowing for startup-time code execution. Attackers can inject variables such as
NODE OPTIONS or LD * through configuration to execute arbitrary code within the OpenClaw gateway service runtime context. The issue stems from the collectConfigEnvVars() function accepting unfiltered keys from configuration, which are then merged into the daemon install environment via buildGatewayInstallPlan(). Prior to the fix, startup-control variables were not blocked in this process.Recommendations
OpenClaw versions prior to 2026.2.21 should be updated to version 2026.2.21 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw