CVE-2026-41369General(openclaw / openclaw)

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environment variables to override critical system configurations and compromise host execution integrity.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-28: 2Technical Details · 2026-04-28: 104-28
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41369 Environment Variable Injection in OpenClaw Before 2026.3.31 Host Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41369

    Post summary

    The entry references CVE-2026-41369 as an environment variable injection in OpenClaw before 2026.3.31, but offers no details about PoC, exploit, patch or active exploitation.

    1000080
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-41369 📊 Severity: 6.5 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41369 #CVE-2026-41369 #CVE #Medium #CyberSecurity #InfoSec https://t.co/hOGK0mSsP9

    Post summary

    A new CVE-2026-41369 vulnerability with medium severity is announced; no further exploitation, patch, or technical details are provided.

    0000040
    142 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more