CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-8634

Critical · CVSS 9.1

github.com/openclaw/crabbox — Environment variable exposure / overly permissive allowlisting leading to credential leakage in remote command execution (CWE-94)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-94

Description

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens into the remote command environment. Attackers can exploit overly permissive environment variable allowlisting in repo-local Crabbox configuration to serialize sensitive environment variables into remote command execution, exposing credentials to the remote environment.

Search profile — drives PoC discovery

Symbols crabboxenvallowlistallowlistingremote command environmentenvironment variable serializationAPI tokenscloud credentialsbroker tokensrepo-local configurationeaae40ae4ce009e60633f16f7f19600c74557f6f
Keywords CVE-2026-8634crabboxopenclawenvironment variable exposurecredential leakageenv allowlistremote command executioncrabbox PoCcrabbox exploitcrabbox v0.12.0CWE-94 crabboxcrabbox PR 78
Versions: < v0.12.0

Affected packages

Go github.com/openclaw/crabbox 0 → 0.12.0

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T06:30:20.000Z