PT-2026-35774 · Openclaw · Openclaw
Longgteng
·
Published
2026-03-31
·
Updated
2026-04-30
·
CVE-2026-41390
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.28
Description
An exec allowlist bypass exists where allow-always persistence fails to unwrap
/usr/bin/script and similar wrappers before storing trust decisions. This allows attackers to obtain user approval for a single wrapped command to persist trust for wrapper binaries that execute different underlying programs.Recommendations
Update to version 2026.3.28.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw