CVE-2026-42435

8.8

OpenClaw · OpenClaw

OpenClaw contains an insufficient shell-wrapper detection vulnerability that allows authenticated attackers to inject environment variable assignments and manipulate security controls.

Executive summary

An insufficient shell-wrapper detection vulnerability in OpenClaw allows authenticated attackers to inject environment variable assignments, posing a severe risk to execution semantics and total system integrity.

Vulnerability

This is an incomplete list of disallowed inputs flaw, tracked as CWE-184, where the application fails to properly detect shell-wrappers, allowing low-privileged authenticated attackers to inject argv-level environment variables.

Business impact

A successful exploit grants attackers the ability to manipulate high-risk shell variables like SHELLOPTS and PS4, leading to a complete compromise of execution semantics and potential total system control. With a high CVSS score of 8.8, this vulnerability presents significant operational and security risks, including unauthorized access and potential data compromise.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.4.12 or later to resolve the shell-wrapper detection issue.

Proactive Monitoring: Review system access and process execution logs for anomalous environment variable assignments or unauthorized modifications to shell configuration parameters.

Compensating Controls: Restrict user permissions to limit low-privileged accounts from executing administrative functions or utilizing affected wrapper scripts until the patch is applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the severity of potential total impact, administrators must prioritize patching this vulnerability immediately. Upgrading to OpenClaw version 2026.4.12 or later is critical to eliminate the risk of environment variable injection and secure execution environments.

More OpenClaw CVEs

Sources