PT-2026-33861 · Openclaw · Openclaw
Tdjackey
·
Published
2026-04-01
·
Updated
2026-04-22
·
CVE-2026-41294
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.28
Description
An environment variable injection issue occurs because the software loads the .env file from the current working directory before the trusted state-dir configuration. This allows untrusted workspace state to inject host environment values. An attacker can place a malicious .env file in a repository or workspace to override runtime configuration and security-sensitive environment settings during startup, potentially leading to configuration takeover and bypassing host-env policy. The issue is located in the
src/infra/dotenv.ts and src/cli/dotenv.ts components.Recommendations
Update to version 2026.3.28.
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw