OpenClaw Incomplete Host Environment Variable Sanitization Vulnerability Allowing Supply-Chain Redirection

Vulnerability

A vulnerability exists in OpenClaw versions prior to 2026.3.22, due to incomplete sanitization of host environment variables in the files host-env-security-policy.json and host-env-security.ts. This flaw allows package-manager environment overrides. Attackers can exploit approved execution requests to redirect package resolution or runtime initialization to infrastructure they control, potentially executing malicious content.

Impact

Exploitation of this vulnerability could lead to unauthorized redirection of package management processes, allowing the execution of trojanized content on the affected system.

Remediation

Users can upgrade to OpenClaw version 2026.3.22 or later to address this vulnerability.

Added: Apr 28, 2026, 9:27 PM
Updated: Apr 28, 2026, 9:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
0.0
relevance
6.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.