Incomplete Host Environment Variable Sanitization in OpenClaw by OpenClaw
CVE-2026-41387
8.5HIGH
What is CVE-2026-41387?
A security flaw in OpenClaw versions prior to 2026.3.22 allows incomplete sanitization of host environment variables in key configuration files. This vulnerability enables attackers to manipulate approved execution requests, resulting in potentially malicious redirection of package resolutions or runtime processes to unauthorized infrastructures. Through this exploitation, an attacker could execute trojanized content, posing significant risks to system integrity and security.
Affected Version(s)
OpenClaw 0 < 2026.3.22
OpenClaw 2026.3.22
