CVE-2026-53858
Severity CVSS v4.0:
HIGH
Type:
CWE-426
Untrusted Search Path
Publication date:
16/06/2026
Last modified:
16/06/2026
Description
OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots. Attackers can manipulate the STATE_DIRECTORY variable to load runtime dependencies from unintended local paths, potentially executing malicious code during dependency resolution.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
7.10
Severity 3.x
HIGH



