CVE-2026-22176 | OpenClaw up to 2026.2.18 Environment Variable gateway.cmd os command injection (GHSA-pj5x-38rw-6fph / WID-SEC-2026-0586)
A vulnerability, which was classified as critical, was found in OpenClaw up to 2026.2.18. The affected element is an unknown function of the file gateway.cmd of the component Environment Variable Handler. The manipulation results in os command injection.
This vulnerability is cataloged as CVE-2026-22176. The attack must be initiated from a local position. There is no exploit available.
You should upgrade the affected component.