CVE-2026-41294 - Vulnerability Analysis
HighCVSS: 8.6Last Updated: April 21, 2026
OpenClaw - Environment Variable Injection
Published: April 21, 2026Updated: April 21, 2026
Overview
OpenClaw before 2026.3.28 contains an environment variable injection caused by loading the current working directory .env file before trusted state-dir configuration, letting attackers override runtime and security-sensitive settings during startup, exploit requires placing a malicious .env file in the workspace.
Severity & Score
Severity: High
CVSS Score: 8.6
Impact
Attackers can override runtime configuration and security-sensitive environment settings, potentially leading to privilege escalation or arbitrary code execution.
Mitigation
Update to version 2026.3.28 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-41294
- Severity
- High
- CVSS Score
- 8.6
- Type
- undefined
- Status
- new
CWE
- CWE-15
CVSS Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H