PT-2026-35780 · Openclaw · Openclaw

Keensecuritylab

+2

·

Published

2026-04-03

·

Updated

2026-04-30

·

CVE-2026-41396

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description Workspace .env files can override the OPENCLAW BUNDLED PLUGINS DIR environment variable, which compromises the verification of plugin trust. This allows attackers who have control over the workspace configuration to inject malicious plugins by overriding the bundled plugin trust root directory.
Recommendations Update to version 2026.3.31.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41396
GHSA-QCJ9-WWGW-6GM8

Affected Products

Openclaw