OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller access or configured input paths can execute or persist actions beyond their intended authorization level.
| Vendor | Product | Versions |
|---|---|---|
| openclaw | openclaw | 0 |
Updated severity to CRITICAL based on 'very critical' classification, estimated CVSS to 9.0, and added CWE-269 (Improper Access Control / Privilege Management) for the improper authorization aspect.
Initial creation