Environment Variable Leakage in OpenClaw SSH Sandboxed Backends
CVE-2026-41357
2LOW
What is CVE-2026-41357?
OpenClaw versions prior to 2026.3.31 exhibit a vulnerability associated with the leakage of environment variables through SSH-based sandbox backends. This issue arises when unsanitized process.environment variables are passed to child processes, potentially allowing attackers to exploit non-default SSH environment forwarding configurations. Through this misconfiguration, sensitive details from parent processes can be leaked into SSH child processes, posing a significant risk to the confidentiality of the environment.
Affected Version(s)
OpenClaw 0 < 2026.3.31
OpenClaw 2026.3.31
