OpenClaw Environment Variable Namespace Collision Vulnerability

Vulnerability

A vulnerability exists in OpenClaw versions prior to 2026.4.20, where the application fails to properly secure the OPENCLAW_ runtime-control environment namespace in workspace dotenv files. This oversight allows attackers to override important runtime variables. Malicious workspaces could manipulate variables such as OPENCLAW_GIT_DIR, potentially altering trusted OpenClaw runtime behavior during source-update or installation processes.

Impact

Exploitation of this vulnerability could lead to unauthorized manipulation of OpenClaw's runtime behavior, particularly during critical update or installation phases.

Remediation

Users can update to OpenClaw version 2026.4.20 or later, where this vulnerability has been addressed.

Added: May 6, 2026, 9:04 PM
Updated: May 6, 2026, 9:04 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.9
remediation
0.0
relevance
7.2
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.