PT-2026-35774 · Openclaw · Openclaw

Longgteng

·

Published

2026-03-31

·

Updated

2026-04-30

·

CVE-2026-41390

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.28
Description An exec allowlist bypass exists where allow-always persistence fails to unwrap /usr/bin/script and similar wrappers before storing trust decisions. This allows attackers to obtain user approval for a single wrapped command to persist trust for wrapper binaries that execute different underlying programs.
Recommendations Update to version 2026.3.28.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41390
GHSA-6PFC-6M7W-M8FX

Affected Products

Openclaw