Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Garagon

#40303of 56,329
7.3Total CVSS
Vulnerabilities · 1
PT-2026-39684
7.3
2026-04-25
Openclaw · Openclaw · CVE-2026-44995
**Name of the Vulnerable Software and Affected Versions** OpenClaw versions prior to 2026.4.20 **Description** Improper environment variable validation in the MCP stdio server configuration allows for arbitrary code execution. Malicious workspace configurations can pass dangerous startup variables, such as `NODE OPTIONS`, `LD PRELOAD`, or `BASH ENV`, to spawned MCP server processes, enabling code injection when operators start sessions using those servers. **Recommendations** Update to version 2026.4.20.