| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vfw7-6rhc-6xxg | OpenClaw Has Incomplete Fix for CVE-2026-4039: CLI Backend Environment Variable Injection via Workspace Config |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 29 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environment variables through workspace configuration. Attackers can craft malicious workspace configs to inject arbitrary environment variables into the backend process spawning, enabling code execution or sensitive data exposure. | |
| Title | OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-15 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-29T15:11:21.165Z
Reserved: 2026-04-20T14:12:09.519Z
Link: CVE-2026-41384
Updated: 2026-04-29T14:11:09.536Z
Status : Analyzed
Published: 2026-04-28T19:37:41.497
Modified: 2026-05-01T15:52:11.340
Link: CVE-2026-41384
No data.
OpenCVE Enrichment
Updated: 2026-04-28T23:15:43Z
Github GHSA