PT-2026-29869 · Openclaw · Openclaw

Zhijie Zhang

·

Published

2026-03-26

·

Updated

2026-04-03

·

CVE-2026-34426

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to commit b57b680
Description OpenClaw is susceptible to an approval bypass due to inconsistent environment variable normalization between approval and execution processes. This allows attackers to inject attacker-controlled environment variables into execution without validation by the approval system. The differing normalization logic discards non-portable keys during approval but accepts them during execution, bypassing operator review and potentially enabling the execution of attacker-controlled binaries.
Recommendations Update OpenClaw to commit b57b680 or later.

Fix

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

CVE-2026-34426
GHSA-8H8F-7CXM-M38J
GHSA-H3X4-HC5V-V2GM

Affected Products

Openclaw