Host exec environment overrides miss proxy, TLS, Docker, and Git TLS controls
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.314d912e04519b4bd53b248437c53748cdebce9a41 — 2026-03-31T21:25:36+09:00OpenClaw thanks @AntAISecurityLab for reporting.
{
"github_reviewed": true,
"github_reviewed_at": "2026-04-03T02:57:00Z",
"cwe_ids": [
"CWE-269",
"CWE-453"
],
"severity": "MODERATE",
"nvd_published_at": "2026-04-21T00:16:31Z"
}