Permissive List of Allowed Inputs in OpenClaw - CVE-2026-41387
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to execute trojanized content.
The vulnerability exists due to permissive list of allowed inputs in src/infra/host-env-security-policy.json and src/infra/host-env-security.ts when processing package-manager and related environment override variables. A remote attacker can cause an approved exec request to use attacker-controlled infrastructure to execute trojanized content.
User interaction is required through an approved exec request, and the issue can redirect package resolution or runtime bootstrap to attacker-controlled infrastructure.