OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-101884

HIGH · CVSS 7.5 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

OpenClaw Windows Node versions prior to 2026.7.1 are vulnerable due to an incomplete environment-variable sanitizer in the system.run function, which fails to properly block certain environment variables. This flaw allows attackers with gateway or agent access to inject malicious code into allowlisted tools such as git, dotnet, or java, potentially leading to arbitrary code execution. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101884
Severity
HIGH
CVSS
7.5
EPSS
0.47%
Windows Java

Original NVD Description

OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.