Impact
A missing environment variable denylist in OpenClaw before 2026.4.8 allows an attacker to inject malicious build‑tool environment variables such as HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS into host execution commands, enabling arbitrary code execution on the host machine that runs the builder.
Affected Systems
OpenClaw deployments using any version older than 2026.4.8, regardless of operating system, are affected when the software runs unfiltered build scripts that may set the listed environment variables.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate severity. The EPSS score is not available, so exploitation probability cannot be quantified, but the vulnerability is not yet listed in CISA KEV. Attackers can potentially introduce malicious variables through remote build interfaces or compromised build scripts, giving them the ability to execute arbitrary host commands. Successful exploitation would provide full control over the build host.
OpenCVE Enrichment