PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.317ae1bb0c7799fd0cbd2d4de7b0f5b8039837ab8d — 2026-03-31T09:53:32+09:00OpenClaw thanks @nexrin for reporting.
{
"nvd_published_at": null,
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-807"
],
"github_reviewed_at": "2026-04-02T20:57:44Z"
}