PT-2026-37007 · Openclaw · Openclaw

Published

2026-04-17

·

Updated

2026-05-05

·

CVE-2026-42435

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.2.22 through 2026.4.11
Description Insufficient shell-wrapper detection allows attackers to inject environment variable assignments at the argv level. This enables the bypass of exec preflight handling to manipulate high-risk shell variables, such as SHELLOPTS and PS4, which can affect execution semantics and security controls.
Recommendations Update to version 2026.4.12 or newer.

Fix

OS Command Injection

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

CVE-2026-42435
GHSA-J6C7-3H5X-99G9

Affected Products

Openclaw