Skip to content

OpenClaw Has Incomplete Fix for CVE-2026-4039: CLI Backend Environment Variable Injection via Workspace Config

High severity GitHub Reviewed Published Mar 31, 2026 in openclaw/openclaw • Updated May 6, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts