Git Environment Variable Injection Vulnerability in OpenClaw by OpenClaw
CVE-2026-41915
5.8MEDIUM
What is CVE-2026-41915?
OpenClaw versions prior to 2026.4.8 contain a vulnerability that allows attackers to manipulate Git plumbing environment variables during execution. This oversight permits the redirection of Git operations, which can lead to the compromise of repository integrity. Not removing GIT_DIR and related variables from the execution context opens the door for malicious agents to influence how Git commands are executed, posing a significant risk to the security and trustworthiness of stored data.
Affected Version(s)
OpenClaw 0 < 2026.4.8
OpenClaw 2026.4.8
