Ghostwire

CVE-2026-35650: OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to...

HIGH CVSS 7.5 EPSS 0.06%

Published: April 10, 2026 | Last Modified: April 10, 2026

Description

OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypass the shared host environment policy through inconsistent sanitization paths. Attackers can supply blocked or malformed override keys that slip through inconsistent validation to execute arbitrary code with unintended environment variables.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.06% (19th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References