MEDIUM
OpenClaw < 2026.4.2 - Approval Integrity Bypass in pnpm dlx Local Script Binding
Published Apr 23, 2026
5.4
MEDIUMCVSS 4.0
EPSS 0.12%
Description
OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. Attackers can replace approved local scripts before execution without invalidating the approval plan, allowing execution of modified script contents.
Affected products
-
- Version 0StatusaffectedConstraints<2026.4.2
- Version 2026.4.2StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.4.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.4.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25344 Advisory
- https://github.com/openclaw/openclaw/commit/176c059b05357df1bc09d4328a2380670859eeff patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-w6wx-jq6j-6mcj vendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-approval-integrity-bypass-in-pnpm-dlx-local-script-binding third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25344 | Advisory | |
| https://github.com/openclaw/openclaw/commit/176c059b05357df1bc09d4328a2380670859eeff | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-w6wx-jq6j-6mcj | vendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-approval-integrity-bypass-in-pnpm-dlx-local-script-binding | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 23, 2026
Updated Apr 24, 2026
Reserved Apr 20, 2026
Link CVE-2026-41360
CISA Vulnrichment
Updated Apr 24, 2026
ENISA EUVD
EUVD-2026-25344 Assigner VulnCheck
Published Apr 23, 2026
Updated Apr 24, 2026
Exploited since n/a
Link EUVD-2026-25344