PT-2026-35805 · Openclaw · Openclaw
Boyhack
·
Published
2026-04-09
·
Updated
2026-04-29
·
CVE-2026-42427
CVSS v4.0
8.6
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.8
Description
Remote code execution is possible due to missing environment variable denylist entries. Attackers can inject malicious build tool environment variables, specifically
HGRCPATH, CARGO BUILD RUSTC WRAPPER, RUSTC WRAPPER, and MAKEFLAGS, to influence host exec commands and achieve arbitrary code execution.Recommendations
Update to version 2026.4.8.
Fix
RCE
Incomplete List of Disallowed Inputs
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw