Incomplete host-env-security-policy.json allows untrusted model to substitute compiler binaries (CC, CXX, CARGO_BUILD_RUSTC, CMAKE_C_COMPILER) via env overrides on approved host exec requests
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.31e277a37f896b5011a1df06e6490c6630074d0afa — 2026-03-30T20:06:32+01:00OpenClaw thanks @tdjackey for reporting.
{
"cwe_ids": [
"CWE-427"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-03T03:00:51Z",
"nvd_published_at": "2026-04-28T19:37:39Z",
"severity": "HIGH"
}