PT-2026-34763 · Openclaw · Openclaw
Nicky
·
Published
2026-04-23
·
Updated
2026-04-23
·
CVE-2026-41332
CVSS v3.1
5.3
Medium
| AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N |
OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT TEMPLATE DIR and AWS CONFIG FILE are not blocked in the host-env blocklist. Attackers can exploit approved exec requests to redirect git or AWS CLI behavior through attacker-controlled configuration files to execute untrusted code or load malicious credentials.
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw