
CVE-2026-44992 OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API_HOST. Attackers … https://www.cve.org/CVERecord?id=CVE-2026-44992
Post summary
The text reports the existence of CVE-2026-44992, an environment variable injection flaw in OpenClaw that allows overriding MINIMAX_API_HOST in affected versions prior to 2026.4.20.
