CVE-2026-22177 | OpenClaw up to 2026.2.20 Gateway Service NODE_OPTIONS external control of setting (GHSA-8fmp-37rc-p5g7)
A vulnerability classified as problematic was found in OpenClaw up to 2026.2.20. This impacts an unknown function of the component Gateway Service. Such manipulation of the argument NODE_OPTIONS leads to external control of system or configuration setting.
This vulnerability is referenced as CVE-2026-22177. The attack can only be performed from a local environment. No exploit is available.
Upgrading the affected component is advised.