OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environment variables through workspace configuration. Attackers can craft malicious workspace configs to inject arbitrary environment variables into the backend process spawning, enabling code execution or sensitive data exposure.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environment variables through workspace configuration. Attackers can craft malicious workspace configs to inject arbitrary environment variables into the backend process spawning, enabling code execution or sensitive data exposure. | |
| Title | OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-15 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-28T18:09:46.894Z
Reserved: 2026-04-20T14:12:09.519Z
Link: CVE-2026-41384
No data.
Status : Awaiting Analysis
Published: 2026-04-28T19:37:41.497
Modified: 2026-04-28T20:10:23.367
Link: CVE-2026-41384
No data.
OpenCVE Enrichment
Updated: 2026-04-28T23:15:43Z