OpenClaw
- <= 2026.6.2
A vulnerability exists in OpenClaw versions prior to 2026.6.6, where the host execution environment variable filtering does not properly sanitize rustup startup variables. This flaw allows attackers with lower-trust caller access or configured input paths to execute or persist actions beyond their intended authorization level.
Exploitation of this vulnerability could lead to unauthorized execution or persistence of actions, exceeding the caller's intended authorization. The actual impact would depend on the operator's configuration and the ability of lower-trust input to access the vulnerable path.
Users are advised to upgrade to OpenClaw version 2026.6.6 or later. Before upgrading, it is recommended to restrict the affected feature to trusted operators or disable it when not needed. As a general practice, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.