Environment Variable Injection in OpenClaw Affects Dependency Management
CVE-2026-53858
7HIGH
What is CVE-2026-53858?
OpenClaw, prior to version 2026.5.2, is susceptible to an environment variable injection vulnerability. This flaw allows attackers to manipulate the STATE_DIRECTORY variable within the workspace .env file, potentially directing the application to load runtime dependencies from unintended local paths. As a result, attackers could execute malicious code during the dependency resolution process, compromising application integrity and security.
Affected Version(s)
OpenClaw 0 < 2026.5.2
OpenClaw 2026.5.2
