Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution. | |
| Title | OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override | |
| Weaknesses | CWE-184 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-30T19:33:24.196Z
Reserved: 2026-09-28T15:44:45.389Z
Link: CVE-2026-101884
No data.
Status : Received
Published: 2026-09-30T20:17:20.663
Modified: 2026-09-30T20:17:20.663
Link: CVE-2026-101884
No data.
OpenCVE Enrichment
Updated: 2026-09-30T20:30:18Z