PT-2026-37327 · Npm · Openclaw

Published

2026-04-25

·

Updated

2026-04-25

CVSS v4.0

5.4

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected versions: < 2026.4.20
  • Patched version: 2026.4.20

Impact

Workspace MCP stdio configuration could pass dangerous process-startup environment variables such as NODE OPTIONS, LD PRELOAD, or BASH ENV to the spawned MCP server process. In a malicious workspace, this could make the MCP child load attacker-controlled code when the operator starts a session that uses that MCP server.
The impact is limited to local/workspace trust boundaries and requires the operator to run OpenClaw in a workspace containing the malicious MCP configuration. Severity is therefore medium, not high/critical.

Fix

OpenClaw now filters MCP stdio environment entries through the host environment safety denylist before spawning stdio MCP servers.
Fix commits:
  • 62fa5071896e95edc7f67d1cebc70a2859e283af
  • 85d86ebc4bf3d2226d39d132a484f4f7a299fa1b

Release

Fixed in OpenClaw 2026.4.20.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-MJ59-H3Q9-GHFH

Affected Products

Openclaw