Openclaw cli: OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config (CVE-2026-44995)
Description
OpenClaw CLI versions before 2026.4.20 contain a vulnerability where the MCP stdio server environment can load dangerous startup variables from workspace configuration. This allows malicious workspaces to pass harmful environment variables like NODE_OPTIONS, LD_PRELOAD, or BASH_ENV to the MCP server process, potentially causing it to load attacker-controlled code. The risk is limited to local or workspace trust boundaries and requires the operator to run OpenClaw in a maliciously configured workspace. The issue is fixed in version 2026.4.20 by filtering unsafe environment variables before spawning MCP servers.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The OpenClaw CLI (npm package) versions prior to 2026.4.20 allow a malicious workspace MCP stdio configuration to pass dangerous environment variables such as NODE_OPTIONS, LD_PRELOAD, or BASH_ENV to the spawned MCP server process. This can lead to the MCP child process loading attacker-controlled code when an operator starts a session using that MCP server. The vulnerability is limited to local trust boundaries and requires user interaction with a malicious workspace. The fix implemented in version 2026.4.20 filters MCP stdio environment entries through a host environment safety denylist before spawning MCP servers.
Potential Impact
An attacker controlling a workspace can cause the MCP server process to load malicious code via environment variables, potentially compromising the operator's session. However, the impact is constrained to local or workspace trust boundaries and requires the operator to run OpenClaw in a malicious workspace. Therefore, the severity is medium rather than high or critical.
Mitigation Recommendations
A patch is available in OpenClaw version 2026.4.20 that filters unsafe environment variables before spawning MCP stdio servers. Operators should upgrade to version 2026.4.20 or later to remediate this vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-44995
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac2459012601ec6a31641e6
Added to database: 10/04/2026, 12:24:48 UTC
Last enriched: 10/04/2026, 12:39:21 UTC
Last updated: 10/04/2026, 16:08:38 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.