PT-2026-31961 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-03-26

·

Updated

2026-04-12

·

CVE-2026-35650

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.22
Description OpenClaw contains a flaw in its handling of environment variable overrides. Inconsistent sanitization paths allow attackers to bypass shared host environment policies by supplying blocked or malformed override keys. This can lead to the execution of arbitrary code with unintended environment variables.
Recommendations Update to version 2026.3.22 or later.

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35650
GHSA-39PP-XP36-Q6MG

Affected Products

Openclaw