openclaw (npm)< 2026.4.202026.4.20Workspace .env loading did not reserve the OPENCLAW_ runtime-control namespace broadly enough. A malicious workspace could set variables such as OPENCLAW_GIT_DIR before source-update or installer flows, potentially steering trusted OpenClaw runtime behavior.
This requires running OpenClaw from an attacker-controlled workspace. Severity is medium.
OpenClaw now reserves the workspace OPENCLAW_ environment namespace and rejects workspace dotenv entries for OpenClaw runtime-control variables.
Fix commit:
018494fa3ebb9145112e68b56fe1cb2e9f9a9ed6Fixed in OpenClaw 2026.4.20.
| Score | Percentile |
|---|---|
| 0.02% | 6.40% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 7.8 | 3.1 | — |
|
| 8.5 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-hxvm-xjvf-93f3 ↗ |
| CVE | CVE-2026-44114 ↗ |
| CWE id | Name |
|---|---|
| CWE-184 | Incomplete List of Disallowed Inputs |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| npm | openclaw | < 2026.4.20 | 2026.4.20 | — |