CVE-2026-53842
HIGH
NVD
CVSS Score
7.1
Severity
HIGH
Published
Jun 16, 2026
Vendor
unknown
Description
OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influence Python runtime selection through CLOUDSDK_PYTHON during Gmail setup gcloud execution. Attackers with repository access can manipulate the CLOUDSDK_PYTHON variable to execute setup through unintended local Python paths, potentially enabling arbitrary code execution.