openclaw/apps
Andrew Demczuk f84a41dcb8
fix(security): block JVM, Python, and .NET env injection vectors in host exec sandbox (#49025)
Add JAVA_TOOL_OPTIONS, _JAVA_OPTIONS, JDK_JAVA_OPTIONS, PYTHONBREAKPOINT, and
DOTNET_STARTUP_HOOKS to blockedKeys in the host exec security policy.

Closes #22681
2026-03-17 15:37:55 +01:00
..
android fix(android): lazy-init node runtime after onboarding 2026-03-16 18:54:51 +05:30
ios build: prepare 2026.3.14 cycle 2026-03-14 06:02:01 +00:00
macos fix(security): block JVM, Python, and .NET env injection vectors in host exec sandbox (#49025) 2026-03-17 15:37:55 +01:00
shared/OpenClawKit fix(plugins): forward plugin subagent overrides (#48277) 2026-03-17 07:20:27 -07:00