CVE-2026-35650 | OpenClaw up to 2026.3.21 Environment Variable external control of setting (GHSA-39pp-xp36-q6mg)
A vulnerability classified as problematic has been found in OpenClaw up to 2026.3.21. This vulnerability affects unknown code of the component Environment Variable Handler. This manipulation causes external control of system or configuration setting.
This vulnerability is tracked as CVE-2026-35650. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.