OpenClaw Environment Variable Injection Vulnerability
Vulnerability
A vulnerability in OpenClaw versions prior to 2026.3.28 allows for environment variable injection by loading the current working directory's .env file before the trusted state-dir configuration. This flaw enables attackers to place a malicious .env file in a repository or workspace, overriding runtime configuration and sensitive security environment settings during OpenClaw's startup.
Impact
Exploitation of this vulnerability could lead to unauthorized modification of runtime configuration and security-sensitive environment variables, potentially allowing for further exploitation or misconfiguration of the application.
Remediation
Users can upgrade to OpenClaw version 2026.3.28 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
