漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend
Vulnerability Description
OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environment variables through workspace configuration. Attackers can craft malicious workspace configs to inject arbitrary environment variables into the backend process spawning, enabling code execution or sensitive data exposure.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
系统设置或配置在外部可控制
Vulnerability Title
OpenClaw 安全漏洞
Vulnerability Description
OpenClaw是OpenClaw开源的一个智能人工助理。 OpenClaw 2026.3.24之前版本存在安全漏洞,该漏洞源于CLI后端运行器中的环境变量注入漏洞,允许攻击者通过工作区配置注入恶意环境变量。攻击者可以制作恶意工作区配置,将任意环境变量注入后端进程生成,实现代码执行或敏感数据泄露。
CVSS Information
N/A
Vulnerability Type
N/A