PT-2026-49759 · Openclaw · Openclaw

·

CVE-2026-53842

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.2
Description An environment variable injection exists where workspace .env files can influence the Python runtime selection during Gmail setup gcloud execution. Attackers with repository access can manipulate the CLOUDSDK PYTHON variable to execute setup through unintended local Python paths, potentially enabling arbitrary code execution. This occurs when a workspace .env in a repository is opened by a trusted operator.
Recommendations Update to version 2026.5.2. Run Gmail setup from trusted workspaces and clear workspace env overrides. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the affected feature when it is not needed.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53842
GHSA-9FR2-P65V-GQXQ
GHSA-FQ9J-VW4W-FR6V

Affected Products

Openclaw