CVE-2026-43531: Openclaw
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control variables. Attackers can inject variables affecting update sources, gateway URLs, ClawHub resolution, and browser executable paths to compromise application behavior.
Affected products
- Openclaw Openclaw: before 2026.4.9 (fixed in 2026.4.9)
Published 2026-05-05. Last modified 2026-06-17.