CVE-2026-41294Patch(openclaw / openclaw)

MEDIUMCVSS 8.5 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing environment variable injection. Attackers can place a malicious .env file in a repository or workspace to override runtime configuration and security-sensitive environment settings during OpenClaw startup.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-15

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-21); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-21: 4Mentions · 2026-04-22: 1Active Exploitation · 2026-04-22: 1Patch / Workaround · 2026-04-21: 2Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-21: 3Technical Details · 2026-04-22: 104-2104-22
Signal classification4 categories
Patch
240.0%
Disclosure
120.0%
General
120.0%
Active Exploitation
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-214
Disclosure1General1Patch2
2026-04-221
Active Exploitation1
Full discourse5 posts
  • Hexxagon@hexxagon_io
    Patch

    @pulsepatchio Great point about the CVE-2026-41294 vulnerability. To mitigate risks, implement strict input validation and sanitize environment variables in your deployment pipeline. At Hexxagon AI, we emphasize secure coding practices and regular audits to prevent such issues in production.

    Post summary

    The post reiterates mitigation steps for CVE‑2026‑41294, emphasizing input validation and environment sanitization, but it does not provide exploit details or a formal patch.

    0001079
    69.1K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical environment variable injection vulnerability (CVE-2026-41294) in `OpenClaw` can lead to config takeover, bypassing host-env policy. Ensure secure CWD practices. #OpenClaw #AppSec #CVE https://www.pulsepatch.io/posts/cve-2026-41294-openclaw-env-injection

    Post summary

    The text highlights a CVE-2026-41294 vulnerability in OpenClaw that allows environment variable injection leading to config takeover, and recommends secure CWD practices as a mitigation.

    1000093
    12 followersView on X
  • klawlikula@klawlikula
    Active Exploitation

    ⚠️ CRITICAL OpenClaw Security Alerts! 🚨 CVE-2026-41329 (CVSS 9.8): Sandbox bypass via heartbeat context inheritance. Actively exploited! Update to 2026.3.31+ immediately. CVE-2026-41294 (CVSS 8.6): Env var injection via .env files. Update to 2026.3.28+. Stay safe! 🐉

    Post summary

    The alert reports two critical CVEs, one of which is actively exploited, and urges users to update to the latest software versions immediately.

    0000057
    3 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41294 OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing environment variable injection. Attackers can… https://www.cve.org/CVERecord?id=CVE-2026-41294

    Post summary

    The content discloses that OpenClaw versions prior to 2026.3.28 are susceptible to environment variable injection due to mishandling of .env files. No proof‑of‑concept, exploit code, active exploitation, or patch information is included.

    0000093
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41294 Environment Variable Injection in OpenClaw Before 2026.3.... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41294 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet references CVE-2026-41294 and cites an environment variable injection flaw in OpenClaw, linking to vulnerability details, but offers no PoC, exploit, patch, or active exploitation information.

    0000032
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more