CVE-2026-62203
OpenClaw OpenClaw, openclaw
OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller access or configured input paths can execute or persist actions beyond their intended authorization level.
- CVSS
- 7.7
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.17