PT-2026-35557 · Openclaw · Openclaw
Tdjackey
·
Published
2026-04-03
·
Updated
2026-04-28
·
CVE-2026-41369
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.31
Description
Insufficient environment variable sanitization in host exec operations allows for the injection of malicious environment variables. The system fails to filter variables related to packages, registries, Docker, compilers, and TLS overrides, which can be used to override critical system configurations and compromise host execution integrity.
Recommendations
Update to version 2026.3.31.
Fix
Exposure of Resource to Wrong Sphere
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw