Openclaw · Openclaw · CVE-2026-53864
**Name of the Vulnerable Software and Affected Versions**
OpenClaw versions prior to 2026.5.26
**Description**
Insufficient sanitization in the host environment sanitizer allows Node.js control variables to bypass validation. Attackers with access to workspace `.env` files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths when a process is launched under the accepted environment.
**Recommendations**
Update to version 2026.5.26.
Avoid inheriting workspace or tool-supplied environment values from untrusted repositories.
Keep channel and tool allowlists narrow.
Avoid sharing one Gateway between mutually untrusted users.
Disable the host environment sanitizer feature when it is not needed.