Vulnerability  ·  2026-10-01

OpenClaw Windows Node env-var sanitizer bypass enables RCE via GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, JAVA_TOOL_OPTIONS

VulnerabilityHigh impactGlobalCVE-2026-101884
The environment-variable sanitizer in system.run blocks many dangerous variables but omits GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS. These let allowlisted binaries load attacker-controlled code, turning an approved tool run into full code execution. The incomplete sanitizer is visible in ExecEnvSanitizer.cs.
Agent orchestration platforms gate which shell commands agents can run; this bypass defeats that allowlist by abusing environment-variable-driven code loading in otherwise-safe tools, a classic agent-code-execution escape that also affects gateways chaining multiple nodes.
An attacker with gateway or agent access supplies attacker-controlled GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, or JAVA_TOOL_OPTIONS environment variables to allowlisted tools (git, dotnet, java) launched through the system.run capability; the tools load attacker-controlled code/config, executing it on the node.
OpenClaw Windows Node before 2026.7.1
Upgrade OpenClaw Windows Node to 2026.7.1 or later.
NVDOpenClaw Windows Node ExecEnvSanitizer sourceFeedly CVE entry
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →