Git Environment Variable Injection Vulnerability in OpenClaw by OpenClaw
CVE-2026-41915

5.8MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-41915?

OpenClaw versions prior to 2026.4.8 contain a vulnerability that allows attackers to manipulate Git plumbing environment variables during execution. This oversight permits the redirection of Git operations, which can lead to the compromise of repository integrity. Not removing GIT_DIR and related variables from the execution context opens the door for malicious agents to influence how Git commands are executed, posing a significant risk to the security and trustworthiness of stored data.

Affected Version(s)

OpenClaw 0 < 2026.4.8

OpenClaw 2026.4.8

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

boyhack (@boy-hack)
.