criticalCVSS 9.1Vulnerability

CVE-2026-8634

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens into the remote command environment. Attackers can exploit overly permissive environment variable allowlisting in repo-local Crabbox configuration to serialize sensitive environment variables into remote command execution, exposing credentials to the remote environment.

Properties

severity
critical
summary
Crabbox: environment variable exposure vulnerability
epss_score
0.00742
cvss_score
9.1
ghsa_published
2026-05-14T21:30:47Z
source_url
https://github.com/advisories/GHSA-fm77-94qm-4894
ghsa_updated
2026-05-21T19:29:24Z
ghsa_id
GHSA-fm77-94qm-4894
cve_id
CVE-2026-8634
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
is_ghsa_only
false
epss_percentile
0.51985

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/openclaw/crabbox

AFFECTS (1)

[Software]go/github.com/openclaw/crabbox

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

Explore deeper with Ninja Signal's threat intelligence graph