HIGH
OpenClaw < 2026.3.31 - Insufficient Environment Variable Sanitization in Host Execution
Published Apr 27, 2026
7.1
HIGHCVSS 4.0
EPSS 0.54%
Description
OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environment variables to override critical system configurations and compromise host execution integrity.
Affected products
-
Affected
- ≥ 0, < 2026.3.31
Unaffected
- 2026.3.31
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.31
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.31 |
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25949 Advisory
- https://github.com/advisories/GHSA-cg7q-fg22-4g98 Advisory
- https://github.com/openclaw/openclaw/commit/eb8de6715f02949c21c4e895fffc8a6dcb00975c patch
- https://github.com/openclaw/openclaw/releases/tag/v2026.3.31
- https://github.com/openclaw/openclaw/security/advisories/GHSA-cg7q-fg22-4g98 vendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-insufficient-environment-variable-sanitization-in-host-execution third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25949 | Advisory | |
| https://github.com/advisories/GHSA-cg7q-fg22-4g98 | Advisory | |
| https://github.com/openclaw/openclaw/commit/eb8de6715f02949c21c4e895fffc8a6dcb00975c | patch | |
| https://github.com/openclaw/openclaw/releases/tag/v2026.3.31 | ||
| https://github.com/openclaw/openclaw/security/advisories/GHSA-cg7q-fg22-4g98 | vendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-insufficient-environment-variable-sanitization-in-host-execution | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 27, 2026
Updated Apr 28, 2026
Reserved Apr 20, 2026
Link CVE-2026-41369
CISA Vulnrichment
Updated Apr 28, 2026
Red Hat
No data
GitHub
Link GHSA-CG7Q-FG22-4G98