← back
CVE-2026-41384

OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend

CVSS 8.5 HIGHEPSS 0.1%CWE-15
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.5EPSS 0.1%KEV nãoPoC Patch referenciado
Lifecycle
28 Apr 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environment variables through workspace configuration. Attackers can craft malicious workspace configs to inject arbitrary environment variables into the backend process spawning, enabling code execution or sensitive data exposure.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
OpenClaw · OpenClaw

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →