Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.31eb8de6715f02949c21c4e895fffc8a6dcb00975c — 2026-03-31T19:37:43+09:00OpenClaw thanks @tdjackey for reporting.
{
"github_reviewed": true,
"github_reviewed_at": "2026-04-03T03:07:13Z",
"cwe_ids": [
"CWE-184",
"CWE-668"
],
"severity": "HIGH",
"nvd_published_at": null
}