Remote Code Execution in OpenClaw by Untrusted Environment Variables
CVE-2026-100570
What is CVE-2026-100570?
OpenClaw versions ranging from 2026.3.28 to below 2026.8.1 have a vulnerability that allows users to execute arbitrary code through the manipulation of the CLOUDSDK_PYTHON_ARGS environment variable. When the application is initiated in a workspace compromised by an attacker, it can inherit malicious command-line arguments upon launching gcloud during the Gmail setup flow. This could lead to the unauthorized execution of Python code under the host user's permissions, enabling attackers to compromise sensitive data, alter files, or initiate additional unauthorized processes. The issue has been addressed in version 2026.8.1, while users are advised to avoid setting up Gmail in untrusted environments and to clear any inherited CLOUDSDK_* variables prior to initiating the setup.
Affected Version(s)
OpenClaw 2026.3.28 < 2026.8.1
OpenClaw 2026.8.1
