MEDIUM
OpenClaw < 2026.3.28 - Arbitrary Code Execution via Mirror Mode Sandbox File Conversion
Published Apr 23, 2026
5.4
MEDIUMCVSS 4.0
EPSS 0.18%
Description
OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sandbox files into workspace hooks. Attackers with mirror mode access can execute arbitrary code on the host during gateway startup by exploiting enabled workspace hooks.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.28
- Version 2026.3.28StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.28
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.28 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25339 Advisory
- https://github.com/advisories/GHSA-42mx-vp8m-j7qh Advisory
- https://github.com/openclaw/openclaw/commit/c02ee8a3a4cb390b23afdf21317aa8b2096854d1 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-42mx-vp8m-j7qh vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41355
- https://www.vulncheck.com/advisories/openshell-arbitrary-code-execution-via-mirror-mode-sandbox-file-conversion third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25339 | Advisory | |
| https://github.com/advisories/GHSA-42mx-vp8m-j7qh | Advisory | |
| https://github.com/openclaw/openclaw/commit/c02ee8a3a4cb390b23afdf21317aa8b2096854d1 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-42mx-vp8m-j7qh | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41355 | ||
| https://www.vulncheck.com/advisories/openshell-arbitrary-code-execution-via-mirror-mode-sandbox-file-conversion | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 23, 2026
Updated May 12, 2026
Reserved Apr 20, 2026
Link CVE-2026-41355
CISA Vulnrichment
Updated Apr 24, 2026
ENISA EUVD
EUVD-2026-25339 GHSA-42MX-VP8M-J7QH Assigner VulnCheck
Published Apr 23, 2026
Updated May 12, 2026
Exploited since n/a
Link EUVD-2026-25339