CVE-2026-62203: OpenClaw < 2026.6.6 Environment Variable Injection via rustup
OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller access or configured input paths can execute or persist actions beyond their intended authorization level.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.6
Event History
Frequently Asked Questions
What is the risk level of CVE-2026-62203?
CVE-2026-62203 has a high severity rating of 7.7.
What is the nature of CVE-2026-62203?
CVE-2026-62203 is an environment variable injection vulnerability affecting OpenClaw versions prior to 2026.6.6.
How does CVE-2026-62203 affect system security?
CVE-2026-62203 allows attackers to execute actions beyond their intended authorization level due to improper sanitization of rustup startup variables.
How can I mitigate CVE-2026-62203?
To fix CVE-2026-62203, update OpenClaw to version 2026.6.6 or later.
What versions of OpenClaw are vulnerable to CVE-2026-62203?
OpenClaw versions before 2026.6.6 are vulnerable to CVE-2026-62203.