#VU125281 Incomplete List of Disallowed Inputs in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to incomplete list of disallowed inputs in the exec environment denylist when processing user-controlled build-tool environment variables. A local user can set hostile environment variables to execute arbitrary code.
This issue is scoped to the product's local trust model.