Skip to main content
Vulnerability Database/CVE-2026-100570

CVE-2026-100570: OpenClaw npm Package RCE Vulnerability

CVE-2026-100570 is a remote code execution flaw in OpenClaw npm package that lets attackers execute arbitrary code via malicious .env files. This post explains its technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-100570 Overview

CVE-2026-100570 affects the OpenClaw npm package in versions >= 2026.3.28 and < 2026.8.1. The flaw allows an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator launches OpenClaw inside an attacker-controlled workspace and runs the Gmail setup flow, the gcloud launcher inherits that value and forwards it as arguments to the trusted Python interpreter. A crafted value causes Python to execute attacker-supplied code with the host user's permissions. The issue is classified as argument injection [CWE-88] and is fixed in version 2026.8.1.

Critical Impact

Attackers who control workspace content can achieve local code execution as the OpenClaw host user, exposing credentials, allowing file modification, and enabling arbitrary process execution.

Affected Products

  • OpenClaw (npm package openclaw) version 2026.3.28 and later
  • OpenClaw versions prior to 2026.8.1
  • Deployments integrating the Gmail setup flow with Google Cloud SDK (gcloud)

Discovery Timeline

  • 2026-09-26 - CVE-2026-100570 published to NVD
  • 2026-09-29 - Last updated in NVD database

Technical Details for CVE-2026-100570

Vulnerability Analysis

The vulnerability is an argument injection flaw [CWE-88] in OpenClaw's handling of inherited environment variables. OpenClaw loads workspace .env files during startup, allowing attacker-controlled content to populate the process environment. One of the variables it fails to filter is CLOUDSDK_PYTHON_ARGS, which the Google Cloud SDK uses to pass additional command-line arguments to its bundled Python interpreter.

When an operator subsequently runs the Gmail setup flow, OpenClaw invokes gcloud. The gcloud launcher reads CLOUDSDK_PYTHON_ARGS and appends the value to the Python command line. Python interprets flags such as -c as directives to execute inline code, giving the attacker a direct path to arbitrary command execution under the operator's user account.

Root Cause

The root cause is unsafe trust in workspace-sourced environment variables. OpenClaw treats .env files as benign configuration input and propagates CLOUDSDK_* variables into child processes without sanitization. The gcloud launcher further compounds the issue by treating CLOUDSDK_PYTHON_ARGS as trusted command-line input to the Python interpreter.

Attack Vector

Exploitation requires an operator to open a malicious workspace in OpenClaw and then trigger the Gmail setup flow. The attacker plants a .env file in the workspace containing a CLOUDSDK_PYTHON_ARGS value designed to invoke Python with an inline execution flag such as -c followed by attacker code. When gcloud launches Python, the arguments are inherited and executed under the OpenClaw host user's privileges. The attacker can then read stored credentials, modify arbitrary files, or spawn additional processes.

No exploitation code is reproduced here. Refer to the GitHub Security Advisory GHSA-5mrc-77hj-xjxv and the VulnCheck Advisory on OpenClaw RCE for detailed technical write-ups.

Detection Methods for CVE-2026-100570

Indicators of Compromise

  • Presence of a .env file in a workspace containing CLOUDSDK_PYTHON_ARGS or other CLOUDSDK_* overrides not placed by the operator.
  • Unexpected child processes spawned by gcloud or python with unusual command-line arguments, especially -c followed by base64 or shell commands.
  • Outbound network connections from Python processes launched by OpenClaw to untrusted hosts shortly after a Gmail setup flow runs.

Detection Strategies

  • Audit workspace .env files for CLOUDSDK_* variables before launching OpenClaw and alert on any that set CLOUDSDK_PYTHON_ARGS.
  • Monitor process ancestry for OpenClaw -> gcloud -> python chains that execute inline code via -c or load non-standard scripts.
  • Baseline normal gcloud invocations and flag deviations in argument length, flag composition, or child-process behavior.

Monitoring Recommendations

  • Enable process command-line logging on hosts running OpenClaw and forward events to a central analytics platform for correlation.
  • Track file access patterns from Python processes launched under OpenClaw, with specific focus on credential stores such as ~/.config/gcloud and SSH keys.
  • Alert on new or modified .env files in developer workspaces that reference Google Cloud SDK environment variables.

How to Mitigate CVE-2026-100570

Immediate Actions Required

  • Upgrade the openclaw npm package to version 2026.8.1 or later across all operator workstations.
  • Audit existing workspaces for untrusted .env files and remove any CLOUDSDK_* variables not explicitly required.
  • Rotate Google Cloud credentials, OAuth tokens, and secrets accessible to any user who ran the Gmail setup flow on an untrusted workspace.

Patch Information

The maintainers resolved the issue in OpenClaw 2026.8.1. The fix prevents workspace-sourced CLOUDSDK_PYTHON_ARGS values from being inherited by the gcloud subprocess. Review the GitHub Security Advisory GHSA-5mrc-77hj-xjxv for commit-level detail and upgrade guidance.

Workarounds

  • Run the Gmail setup flow only from workspaces whose contents are fully trusted and reviewed.
  • Clear inherited CLOUDSDK_* environment variables in the shell before starting OpenClaw, for example by unsetting them explicitly.
  • Restrict which users can open arbitrary workspaces in OpenClaw and treat .env files from external sources as untrusted input.
bash
# Clear CLOUDSDK_* variables before launching OpenClaw
for v in $(env | awk -F= '/^CLOUDSDK_/ {print $1}'); do unset "$v"; done
npm install -g openclaw@2026.8.1
openclaw

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.