LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-41294

CVE-2026-41294 - Vulnerability Analysis

HighCVSS: 8.6

Last Updated: April 21, 2026

OpenClaw - Environment Variable Injection

Published: April 21, 2026Updated: April 21, 2026

Overview

OpenClaw before 2026.3.28 contains an environment variable injection caused by loading the current working directory .env file before trusted state-dir configuration, letting attackers override runtime and security-sensitive settings during startup, exploit requires placing a malicious .env file in the workspace.

Severity & Score

Severity: High
CVSS Score: 8.6

Impact

Attackers can override runtime configuration and security-sensitive environment settings, potentially leading to privilege escalation or arbitrary code execution.

Mitigation

Update to version 2026.3.28 or later.

Details

CVE ID
CVE-2026-41294
Severity
High
CVSS Score
8.6
Type
undefined
Status
new

CWE

  • CWE-15

CVSS Metrics

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H