CVE-2026-101884
HIGHOpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet,...
Full CISO analysis pending enrichment.
How severe is it?
What is the attack surface?
What should I do?
No patch available
Monitor for updates. Consider compensating controls or temporary mitigations.
Which compliance frameworks are affected?
Compliance analysis pending. Sign in for full compliance mapping when available.
Frequently Asked Questions
What is CVE-2026-101884?
OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.
Is CVE-2026-101884 actively exploited?
No confirmed active exploitation of CVE-2026-101884 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-101884?
No patch is currently available. Monitor vendor advisories for updates.
What is the CVSS score for CVE-2026-101884?
CVE-2026-101884 has a CVSS v3.1 base score of 7.5 (HIGH).
What are the technical details?
Original Advisory
OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.
Weaknesses (CWE)
CWE-184 — Incomplete List of Disallowed Inputs: The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
- [Implementation] Do not rely exclusively on detecting disallowed inputs. There are too many variants to encode a character, especially when different environments are used, so there is a high likelihood of missing some variants. Only use detection of disallowed inputs as a mechanism for detecting suspicious activity. Ensure that you are using other protection mechanisms that only identify "good" input - such as lists of allowed inputs - and ensure that you are properly encoding your outputs.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H References
- github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/ExecEnvSanitizer.cs
- github.com/openclaw/openclaw-windows-node/commit/261ba11aaad671834ad141bb85101b50cf1a38f6
- github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1
- github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-39cf-qcfw-g8pg
- vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-remote-code-execution-via-environment-override