PT-2026-33861 · Openclaw · Openclaw

Tdjackey

·

Published

2026-04-01

·

Updated

2026-04-22

·

CVE-2026-41294

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.28
Description An environment variable injection issue occurs because the software loads the .env file from the current working directory before the trusted state-dir configuration. This allows untrusted workspace state to inject host environment values. An attacker can place a malicious .env file in a repository or workspace to override runtime configuration and security-sensitive environment settings during startup, potentially leading to configuration takeover and bypassing host-env policy. The issue is located in the src/infra/dotenv.ts and src/cli/dotenv.ts components.
Recommendations Update to version 2026.3.28.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41294
GHSA-8RH7-6779-CJQQ

Affected Products

Openclaw