Improper Neutralization of Special Elements in Output Used by a Downstream Component in OpenClaw - CVE-2026-41357
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper neutralization of environment variables in SSH-based sandbox backends when spawning child processes. A local user can influence process.env values passed to local SSH child processes to disclose sensitive information.
Remote leakage depends on non-default SSH environment forwarding.