PT-2026-35775 · Openclaw · Openclaw
Keensecuritylab
+2
·
Published
2026-04-28
·
Updated
2026-04-28
·
CVE-2026-41391
CVSS v3.1
5.3
Medium
| AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N |
OpenClaw before 2026.3.31 fails to properly sanitize PIP INDEX URL and UV INDEX URL environment variables in host execution contexts, allowing attackers to redirect Python package-index traffic. Attackers can exploit this bypass to intercept or manipulate package management operations by injecting malicious index URLs through unsanitized environment variables.
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw