Impact
OpenClaw Windows Node contains an incomplete environment-variable sanitizer in its system.run function that fails to block the GIT_CONFIG_, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Because these variables can be supplied by an attacker with gateway or agent access, a malicious user can cause allowed tools such as git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution. This flaw is a CWE‑184 type problem, where untrusted data is incorrectly handled, resulting in full compromise of the affected node with potential data theft, service disruption, and loss of control.
Affected Systems
The vulnerability affects OpenClaw Windows Node, versions prior to 2026.7.1, released by the vendor OpenClaw. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The CVSS score of 7.7 indicates a high risk. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have gateway or agent-level access to inject the restricted environment variables before system.run executes; the vector is therefore internal, but the impact is severe. Because the flaw leverages trusted third‑party tools, it can be triggered with relative ease by anyone who can influence the environment. The lack of public exploitation does not diminish the high severity and the need for prompt remediation.
OpenCVE Enrichment