MEDIUM
OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy
Published Apr 20, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.18%
Description
OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to properly enforce proxy, TLS, Docker, and Git TLS controls. Attackers can bypass security controls by overriding environment variables to circumvent proxy settings, TLS verification, Docker restrictions, and Git TLS enforcement.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.31
- Version 2026.3.31StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.31
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.31 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24018 Advisory
- https://github.com/advisories/GHSA-9gp8-hjxr-6f34 Advisory
- https://github.com/openclaw/openclaw/commit/4d912e04519b4bd53b248437c53748cdebce9a41 patch
- https://github.com/openclaw/openclaw/releases/tag/v2026.3.31
- https://github.com/openclaw/openclaw/security/advisories/GHSA-9gp8-hjxr-6f34 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41330
- https://www.vulncheck.com/advisories/openclaw-environment-variable-override-via-host-exec-policy third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24018 | Advisory | |
| https://github.com/advisories/GHSA-9gp8-hjxr-6f34 | Advisory | |
| https://github.com/openclaw/openclaw/commit/4d912e04519b4bd53b248437c53748cdebce9a41 | patch | |
| https://github.com/openclaw/openclaw/releases/tag/v2026.3.31 | ||
| https://github.com/openclaw/openclaw/security/advisories/GHSA-9gp8-hjxr-6f34 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41330 | ||
| https://www.vulncheck.com/advisories/openclaw-environment-variable-override-via-host-exec-policy | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 20, 2026
Updated Apr 21, 2026
Reserved Apr 20, 2026
Link CVE-2026-41330
CISA Vulnrichment
Updated Apr 21, 2026
ENISA EUVD
EUVD-2026-24018 GHSA-9GP8-HJXR-6F34 Assigner VulnCheck
Published Apr 20, 2026
Updated Apr 21, 2026
Exploited since n/a
Link EUVD-2026-24018