CVE-2026-43584 | OpenClaw up to 2026.4.9 Environment Variable VIMINIT/EXINIT/LUA_INIT/HOSTALIASES incomplete blacklist (GHSA-vfp4-8x56-j7c5)
A vulnerability identified as critical has been detected in OpenClaw up to 2026.4.9. The affected element is an unknown function of the component Environment Variable Handler. This manipulation of the argument VIMINIT/EXINIT/LUA_INIT/HOSTALIASES causes incomplete blacklist.
This vulnerability is handled as CVE-2026-43584. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.