CVE-2026-43584 POC (Proof-of-Concept)

CVE-2026-43584 POC (Proof-of-Concept)

OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment policy that allows operator-supplied overrides of high-risk interpreter startup variables including VIMINIT, EXINIT, LUA_INIT, and HOSTALIASES. Attackers can exploit this by manipulating these environment variables to influence downstream execution behavior or network connectivity.

Published: 2026-05-06

CVSS: 8.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Download CVE-2026-43584 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

https://hokyo.gr/poc-417-cve-2026-34464/

https://hokyo.gr/poc-684-cve-2026-6692/

https://hokyo.gr/poc-405-cve-2026-32603/

https://hokyo.gr/poc-144-cve-2025-63548/

https://hokyo.gr/poc-391-cve-2026-25243/

Copyright 2017- 2025 Hokyo JapanEats ©