What happened
The environment-variable sanitizer in system.run blocks many dangerous variables but omits GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS. These let allowlisted binaries load attacker-controlled code, turning an approved tool run into full code execution. The incomplete sanitizer is visible in ExecEnvSanitizer.cs.
Why it matters
Agent orchestration platforms gate which shell commands agents can run; this bypass defeats that allowlist by abusing environment-variable-driven code loading in otherwise-safe tools, a classic agent-code-execution escape that also affects gateways chaining multiple nodes.
Attack vector
An attacker with gateway or agent access supplies attacker-controlled GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, or JAVA_TOOL_OPTIONS environment variables to allowlisted tools (git, dotnet, java) launched through the system.run capability; the tools load attacker-controlled code/config, executing it on the node.
Affected systems
OpenClaw Windows Node before 2026.7.1
Mitigation
Upgrade OpenClaw Windows Node to 2026.7.1 or later.