CVE-2026-43531: Openclaw

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control variables. Attackers can inject variables affecting update sources, gateway URLs, ClawHub resolution, and browser executable paths to compromise application behavior.

Affected products

  • Openclaw Openclaw: before 2026.4.9 (fixed in 2026.4.9)

Published 2026-05-05. Last modified 2026-06-17.