CVE-2026-42435 | OpenClaw up to 2026.4.11 Environment Variable incomplete blacklist
A vulnerability described as critical has been identified in OpenClaw up to 2026.4.11. Affected by this issue is some unknown functionality of the component Environment Variable Handler. Such manipulation leads to incomplete blacklist.
This vulnerability is uniquely identified as CVE-2026-42435. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.