Environment Variable Filtering Vulnerability in OpenClaw by OpenClaw
CVE-2026-62203

7.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62203?

OpenClaw, in versions before 2026.6.6, exhibits an environment variable filtering vulnerability in its host exec function. This flaw arises from inadequate sanitization of startup variables linked to rustup, allowing attackers with lower-trust access to execute unauthorized actions or to maintain persistence beyond their designated permissions. This vulnerability poses significant risks for systems relying on OpenClaw, potentially granting elevated access to malicious actors.

Affected Version(s)

OpenClaw 0 < 2026.6.6

OpenClaw 2026.6.6

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seokjun Ryu (@SEORY0)
.