Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-53842

HIGH NVD
CVSS Score 7.1
Severity HIGH
Published Jun 16, 2026
Vendor unknown

Description

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influence Python runtime selection through CLOUDSDK_PYTHON during Gmail setup gcloud execution. Attackers with repository access can manipulate the CLOUDSDK_PYTHON variable to execute setup through unintended local Python paths, potentially enabling arbitrary code execution.

References