CVE-2026-101884

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.5
HIGH

Description

OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.

Published
September 30, 2026 8:17 PM
Last Modified
September 30, 2026 8:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-184

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.