Insufficient Environment Variable Denylist in OpenClaw by OpenClaw
CVE-2026-43584

8.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
6 May 2026

What is CVE-2026-43584?

OpenClaw prior to version 2026.4.10 contains a significant vulnerability within its execution policy, resulting from an insufficient denylist for environment variables. This flaw permits attackers to manipulate critical interpreter startup variables, such as VIMINIT, EXINIT, LUA_INIT, and HOSTALIASES. By exploiting this vulnerability, they can influence downstream execution behaviors and modify network connectivity, posing severe risks to system integrity and security.

Affected Version(s)

OpenClaw 0 < 2026.4.10

OpenClaw 2026.4.10

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

feiyang666
.