CVE-2026-101884
Received Received - Intake

OpenClaw Windows Node Environment Variable Injection Flaw

Vulnerability report for CVE-2026-101884, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw windows_node to 2026.7.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an incomplete environment-variable sanitizer in OpenClaw Windows Node before version 2026.7.1. The sanitizer fails to block specific environment variables like GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS. Attackers with access can exploit these variables to inject malicious code through allowlisted tools such as git, dotnet, or java, leading to arbitrary code execution on the host system.

Detection Guidance

Check for the presence of OpenClaw Windows Node versions before 2026.7.1 using system inventory tools or package managers. Inspect environment variable handling in system.run commands for unblocked GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, JAVA_TOOL_OPTIONS, and similar variables. Review logs for unexpected tool invocations like git, dotnet, or java with these variables.

Impact Analysis

An attacker with gateway or agent access could exploit this flaw to execute arbitrary code on your system. This could lead to unauthorized access, data theft, system compromise, or further lateral movement within a network. The impact includes high risks to confidentiality, integrity, and availability of affected systems.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance risks include legal penalties, reputational damage, and loss of trust due to potential breaches of sensitive data.

Mitigation Strategies

Upgrade OpenClaw Windows Node to version 2026.7.1 or later to apply the fixed sanitizer. Block the listed environment variables at the system or application level. Restrict access to tools like git, dotnet, and java to prevent unauthorized variable injection. Monitor for suspicious environment variable usage in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101884. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart