
CVE-2026-41332 OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in the host-env block… https://www.cve.org/CVERecord?id=CVE-2026-41332
Post summary
The tweet announces CVE‑2026‑41332 in OpenClaw, detailing that GIT_TEMPLATE_DIR and AWS_CONFIG_FILE environment variables are not blocked in the host‑env block, but provides no PoC, exploit, patch, or evidence of active exploitation.
