Insecure DLL loading in OpenClaw - CVE-2026-41373
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to execute unintended compiler binaries.
The vulnerability exists due to uncontrolled search path elements in host-env-security-policy.json when processing approved host exec requests with environment overrides. A remote user can supply overridden compiler-related environment variables to execute unintended compiler binaries.
Exploitation requires an approved host-exec request inside the existing exec trust domain.