PT-2026-31961 · Openclaw · Openclaw
Peng Zhou
·
Published
2026-03-26
·
Updated
2026-04-12
·
CVE-2026-35650
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.22
Description
OpenClaw contains a flaw in its handling of environment variable overrides. Inconsistent sanitization paths allow attackers to bypass shared host environment policies by supplying blocked or malformed override keys. This can lead to the execution of arbitrary code with unintended environment variables.
Recommendations
Update to version 2026.3.22 or later.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw