OpenClaw: Workspace dotenv files cannot override connector endpoint hosts
Moderate severity
GitHub Reviewed
Published
Apr 23, 2026
in
openclaw/openclaw
•
Updated May 19, 2026
Description
Published to the GitHub Advisory Database
May 4, 2026
Reviewed
May 4, 2026
Last updated
May 19, 2026
Summary
Workspace dotenv files cannot override connector endpoint hosts.
Affected Packages / Versions
Impact
A workspace .env file could set connector endpoint variables for Matrix, Mattermost, IRC, or Synology-related connectors and redirect runtime traffic away from the operator-configured endpoint.
Fix
Workspace .env loading now blocks those endpoint variables, including per-account Matrix homeserver suffixes and generic base-url/API-host style overrides. Trusted global runtime dotenv loading remains separate.
Fix Commit(s)
Verification
OpenClaw thanks @qi-scape for reporting.
References