CVE-2026-4039
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-74
Neutralización incorrecta de elementos especiales en la salida utilizada por un componente interno (Inyección)
Fecha de publicación:
12/03/2026
Última modificación:
12/03/2026
Descripción
*** Pendiente de traducción *** A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill Env Handler. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. Upgrading to version 2026.2.21-beta.1 is able to resolve this issue. This patch is called 8c9f35cdb51692b650ddf05b259ccdd75cc9a83c. It is recommended to upgrade the affected component.
Impacto
Puntuación base 4.0
5.30
Gravedad 4.0
MEDIA
Puntuación base 3.x
6.30
Gravedad 3.x
MEDIA
Puntuación base 2.0
6.50
Gravedad 2.0
MEDIA
Referencias a soluciones, herramientas e información
- https://github.com/openclaw/openclaw/
- https://github.com/openclaw/openclaw/commit/8c9f35cdb51692b650ddf05b259ccdd75cc9a83c
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.21-beta.1
- https://github.com/openclaw/openclaw/security/advisories/GHSA-82g8-464f-2mv7
- https://vuldb.com/?ctiid_350651=
- https://vuldb.com/?id_350651=
- https://vuldb.com/?submit_769580=



