OpenClaw Environment Variable Injection Vulnerability

Vulnerability

A vulnerability allowing environment variable injection has been identified in OpenClaw versions prior to 2026.4.9. This issue arises from the application's ability to load workspace .env files, which can be manipulated to include runtime-control variables. Such variables could disrupt application behavior by altering update sources, gateway URLs, ClawHub resolutions, and browser executable paths.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in how OpenClaw operates, potentially allowing malicious actors to manipulate key application functions and integrations.

Reproduction

The vulnerability can be reproduced by creating a workspace .env file that includes specific OpenClaw runtime-control variables. Once this file is loaded by the application, the injected variables will take effect, altering the application's behavior according to the values provided.

Remediation

Users are advised to upgrade to OpenClaw version 2026.4.9 or later. The latest version available on npm, 2026.4.14, includes the necessary fix.

Added: May 5, 2026, 12:33 PM
Updated: May 5, 2026, 12:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
7.5
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.