Skip to content
CVE Alert: CVE-2026-101884 – OpenClaw

CVE Alert: CVE-2026-101884 – OpenClaw

Redpacketsecurity •admin • October 1, 2026

OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.

**Risk verdict:** Prioritise remediation promptly: proof-of-concept activity is recorded, but no KEV listing or EPSS value is provided, so active exploitation likelihood is uncertain.

**Why this matters:** An attacker who already has gateway or agent access could turn an approved tool launch into code execution on a Windows node. This could expose data, alter files or services, and disrupt workloads; the reported technical impact is total on the vulnerable node, though broader impact is not established.

**Most likely attack path:** The attacker reaches the service over the network with low-level privileges; no victim interaction is needed. A vulnerable node must be present, and execution depends on an allowlisted tool such as Git, .NET or Java being invoked with attacker-controlled environment overrides. The impact is confined to the node’s security authority in the supplied assessment, so lateral movement is possible only if that node’s access or credentials enable it.

**Who is most exposed:** Organisations using Windows nodes connected to OpenClaw gateways or agents, especially where those nodes can invoke developer or runtime tools. Exposure depends on gateway access controls and which tools are enabled.

Review node logs for unusual `system.run` requests and tool invocations.

Alert on unexpected environment overrides involving Git, .NET or Java.

Check for new processes, files or persistence following tool execution.

Mitigation and prioritisation

Upgrade affected nodes to the vendor-fixed release as soon as practical; verify rollout.

Temporarily restrict gateway/agent access and disable unnecessary tool execution.

Review node credentials and investigate suspicious executions before rotation.

Use a staged change with post-upgrade validation; obtain KEV and EPSS status to refine urgency.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (2)

Tools (1)