CVE-2026-24763 | OpenClaw/Clawdbot/Moltbot up to 2026.1.28 Environment Variable PATH os command injection (GHSA-mc68-q9jw-2h3v)
A vulnerability described as critical has been identified in OpenClaw, Clawdbot and Moltbot up to 2026.1.28. The affected element is an unknown function of the component Environment Variable Handler. The manipulation of the argument PATH results in os command injection.
This vulnerability is identified as CVE-2026-24763. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.