PT-2026-35775 · Openclaw · Openclaw

Keensecuritylab

+2

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-41391

CVSS v3.1

5.3

Medium

AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N
OpenClaw before 2026.3.31 fails to properly sanitize PIP INDEX URL and UV INDEX URL environment variables in host execution contexts, allowing attackers to redirect Python package-index traffic. Attackers can exploit this bypass to intercept or manipulate package management operations by injecting malicious index URLs through unsanitized environment variables.

Fix

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

CVE-2026-41391

Affected Products

Openclaw