PT-2026-35769 · Openclaw · Openclaw

Edward-X

·

Published

2026-04-07

·

Updated

2026-05-01

·

CVE-2026-41384

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.24
Description An environment variable injection issue exists in the CLI backend runner. Attackers can use malicious workspace configurations to inject arbitrary environment variables into the backend process spawning, which may lead to code execution or the exposure of sensitive data.
Recommendations Update to version 2026.3.24.

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2026-41384
GHSA-VFW7-6RHC-6XXG

Affected Products

Openclaw