PT-2026-33872 · Openclaw · Openclaw
Antaisecuritylab
·
Published
2026-04-03
·
Updated
2026-04-21
·
CVE-2026-41330
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.31
Description
An environment variable override issue exists in the host exec policy that fails to properly enforce proxy, TLS, Docker, and Git TLS controls. This allows attackers to bypass security controls by overriding environment variables to circumvent proxy settings, TLS verification, Docker restrictions, and Git TLS enforcement.
Recommendations
Update to version 2026.3.31 or later.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw