PT-2026-35780 · Openclaw · Openclaw

Keensecuritylab

+2

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-41396

CVSS v3.1

7.8

High

AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW BUNDLED PLUGINS DIR environment variable, compromising plugin trust verification. Attackers with control over workspace configuration can inject malicious plugins by overriding the bundled plugin trust root directory.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-41396

Affected Products

Openclaw