CVE-2026-42435

OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing attackers to inject environment variable assignments at the argv level. Attackers can bypass exec preflight handling to manipulate high-risk shell variables like SHELLOPTS and PS4, affecting execution semantics and security controls.
Configurations

No configuration.

History

05 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-05 12:16

Updated : 2026-05-05 19:47


NVD link : CVE-2026-42435

Mitre link : CVE-2026-42435

CVE.ORG link : CVE-2026-42435


JSON object : View

Products Affected

No product.

CWE
CWE-184

Incomplete List of Disallowed Inputs