PT-2026-24944 · Openclaw · Openclaw

·

CVE-2026-4039

·

Published

2026-02-27

·

Updated

2026-04-07

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.2.19-2
Description A flaw exists in the applySkillConfigenvOverrides function within the Skill Env Handler component. This issue allows for code injection when a manipulation is executed remotely. The issue arises because the function copies skills.entries.*.env values into the host process.env without applying host environment safety policies, potentially allowing injection of dangerous process-level variables like NODE OPTIONS. An attacker must be able to modify OpenClaw local state or configuration to set skills.entries.<skill>.env or related skill config values.
Recommendations Upgrade to OpenClaw version 2026.2.21-beta.1 to resolve this issue.

Exploit

Fix

Code Injection

Special Elements Injection

Multiple Releases of Same Resource or Handle

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4039
GHSA-82G8-464F-2MV7
GHSA-WGX8-R9VW-2W4H

Affected Products

Openclaw