PT-2026-49781 · Openclaw · Openclaw

·

CVE-2026-53864

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.26
Description Insufficient sanitization in the host environment sanitizer allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths when a process is launched under the accepted environment.
Recommendations Update to version 2026.5.26. Avoid inheriting workspace or tool-supplied environment values from untrusted repositories. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the host environment sanitizer feature when it is not needed.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53864
GHSA-CCWH-WWPP-6WG5
GHSA-VR6H-VXQJ-3PJX

Affected Products

Openclaw