HIGH
OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend
Published Apr 28, 2026
8.7
HIGHCVSS 4.0
EPSS 0.21%
Description
OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environment variables through workspace configuration. Attackers can craft malicious workspace configs to inject arbitrary environment variables into the backend process spawning, enabling code execution or sensitive data exposure.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.24
- Version 2026.3.24StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.24
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.24 |
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26093 Advisory
- https://github.com/advisories/GHSA-vfw7-6rhc-6xxg Advisory
- https://github.com/openclaw/openclaw/commit/c2fb7f1948c3226732a630256b5179a60664ec24 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-vfw7-6rhc-6xxg vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41384
- https://www.vulncheck.com/advisories/openclaw-environment-variable-injection-via-workspace-config-in-cli-backend third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26093 | Advisory | |
| https://github.com/advisories/GHSA-vfw7-6rhc-6xxg | Advisory | |
| https://github.com/openclaw/openclaw/commit/c2fb7f1948c3226732a630256b5179a60664ec24 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-vfw7-6rhc-6xxg | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41384 | ||
| https://www.vulncheck.com/advisories/openclaw-environment-variable-injection-via-workspace-config-in-cli-backend | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 28, 2026
Updated Apr 29, 2026
Reserved Apr 20, 2026
Link CVE-2026-41384
CISA Vulnrichment
Updated Apr 29, 2026
ENISA EUVD
EUVD-2026-26093 GHSA-VFW7-6RHC-6XXG Assigner VulnCheck
Published Apr 28, 2026
Updated Apr 29, 2026
Exploited since n/a
Link EUVD-2026-26093