PT-2026-99206 · Openclaw · Openclaw
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.3.28 through 2026.8.0
Description
An issue exists where an untrusted workspace .env file can set the
CLOUDSDK PYTHON ARGS environment variable. If an operator starts the software within attacker-controlled workspace content and initiates the Gmail setup flow, this value is inherited by the gcloud launcher and passed as arguments to the trusted Python interpreter. A specially crafted CLOUDSDK PYTHON ARGS value can lead to the execution of arbitrary code with the permissions of the host user, potentially allowing the reading of credentials, modification of files, or initiation of other processes.Recommendations
Update to version 2026.8.1.
Run Gmail setup only from trusted workspaces.
Clear inherited
CLOUDSDK * variables before starting the setup flow.Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw