Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2932 articles · 183577 vulns · 37/41 feeds (7d)
← Back to list
9.0
CVE-2026-62203PATCHED
openclaw · openclaw

OpenClaw < 2026.6.6 Environment Variable Injection via rustup

Description

OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller access or configured input paths can execute or persist actions beyond their intended authorization level.

Affected Products

VendorProductVersions
openclawopenclaw0

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-wxh3-g47h-q3mc(vendor-advisory)
  • https://www.vulncheck.com/advisories/openclaw-environment-variable-injection-via-rustup(third-party-advisory)

Related News (1 articles)

Tier C
VulDB18d ago
CVE-2026-62203 | OpenClaw up to 2026.6.5 Host Exec improper authorization
→ No new info (linked only)
CVSS 3.19.0 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.6.6
CWECWE-184
PublishedJul 17, 2026
Last enriched18d agov2
Trending Score3
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-62220
OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass
Trending: 4
CRITICALCVE-2026-62198
OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search
Trending: 3
NONECVE-2026-62229EXP
OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching
Trending: 3
NONECVE-2026-62207
OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools
Trending: 3
NONECVE-2026-62223
OpenClaw < 2026.5.18 Authorization Bypass via Device-pair
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 17, 2026
Discovered by ZDM
Jul 17, 2026
Updated: severity, cvssEstimate, cweIds
Jul 17, 2026
Patch Available
Jul 29, 2026

Version History

v2
Last enriched 18d ago
v2Tier C18d ago

Updated severity to CRITICAL based on 'very critical' classification, estimated CVSS to 9.0, and added CWE-269 (Improper Access Control / Privilege Management) for the improper authorization aspect.

severitycvssEstimatecweIds
via VulDB
v118d ago

Initial creation