T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:185- Finding
Unsigned release metadata can replace the installed Skill with mutable remote content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a legitimate security advisory feed, but its standalone install/update instructions can trust mutable remote files enough to replace the installed skill.
Review before installing. Prefer a pinned release and the signed-manifest verification path, avoid the README quick install and mutable latest-release installer on production systems, and treat feed advisory text as untrusted data that should not cause commands, file changes, removals, or disclosures without explicit user confirmation.
SKILL.md:185Unsigned release metadata can replace the installed Skill with mutable remote content
SKILL.md:531Unsigned advisory content crosses directly into the agent instruction and notification context
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
"id": "CVE-2026-41357",
"severity": "low",
"type": "unknown_cwe_214",
"nvd_category_id": "CWE-214",
"title": "OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbo...",
"description": "OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass unsanitized process.env to child processes. Attackers can exploit this by leveraging non-default SSH environment forwarding configurations to leak sensitive environment variables from parent processes to SSH child processes.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"openclaw@*"
],
"platforms": [
"openclaw"
],
"action": "Review and update affected components. See NVD for remediation details.",
"published": "2026-04-23T22:16:43.177",
"references": [
"https://github.com/openclaw/openclaw/commit/cfe14459531e0
Referenced artifact was not completely inspected
The default `feed.json` is the consolidated agent feed. It includes NVD CVEs, approved community advisories, and provisional GitHub Security Advisories that do
Referenced artifact was not completely inspected
For standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metad
Referenced artifact was not completely inspected
For standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metad
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
{
"version": "0.0.3",
"updated": "2026-06-21T07:41:37Z",
"description": "Community-driven security advisory feed for ClawSec. Automatically updated with OpenClaw-related CVEs from NVD and community-reported security incidents.",
"advisories": [
{
"id": "CVE-2026-53866",
"severity": "high",
"type": "missing_authorization",
"nvd_category_id": "CWE-862",
"title": "OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing...",
"description": "OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated op
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "unknown_cwe_184",
"nvd_category_id": "CWE-184",
"title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
"description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
9",
"severity": "medium",
"type": "unknown_cwe_1023",
"nvd_category_id": "CWE-1023",
"title": "OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass ...",
"description": "OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. Attackers can exploit inconsistent hostname checks to reach destinations that operators intended to block through hostname policies.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
"cpe:2.3:a:openclaw:openclaw:2026.5.26:beta2:*:*:*:node.js:*:*",
"openclaw@*"
],
"platforms": [
"openclaw"
],
"action": "Review and update affected components. See NVD for remediation details.",
"published": "2026-06-16T19:1
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
"type": "server_side_request_forgery",
"nvd_category_id": "CWE-918",
"title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
"description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"openclaw@*"
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
"type": "server_side_request_forgery",
"nvd_category_id": "CWE-918",
"title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
"description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"openclaw@*"
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
"type": "server_side_request_forgery",
"nvd_category_id": "CWE-918",
"title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
"description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"openclaw@*"
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
"type": "server_side_request_forgery",
"nvd_category_id": "CWE-918",
"title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
"description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"openclaw@*"
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
"type": "server_side_request_forgery",
"nvd_category_id": "CWE-918",
"title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
"description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"openclaw@*"
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
"type": "server_side_request_forgery",
"nvd_category_id": "CWE-918",
"title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
"description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
"affected": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
"openclaw@*"
Detected: suspicious.install_untrusted_source