
CVE-2026-41373 OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models… https://www.cve.org/CVERecord?id=CVE-2026-41373
Post summary
The post discloses that OpenClaw prior to 2026.3.31 suffers from an incomplete host‑env‑security‑policy.json, which permits untrusted models due to unrestricted compiler environment variables, but it lacks PoC, exploit code, or active attack evidence.
