
CVE-2026-41391 OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execution contexts, allowing attackers to redirect P… https://www.cve.org/CVERecord?id=CVE-2026-41391
Post summary
The message announces a security flaw in OpenClaw that improperly sanitizes PIP_INDEX_URL and UV_INDEX_URL, potentially letting attackers redirect package sources, but no PoC, exploit, or patch information is given.
