CVE-2026-41294
HIGHDescription
OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing environment variable injection. Attackers can place a malicious .env file in a repository or workspace to override runtime configuration and security-sensitive environment settings during OpenClaw startup.
Is your site exposed to CVE-2026-41294?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| openclaw | openclaw |
References
Frequently Asked Questions
What is CVE-2026-41294? +
How severe is CVE-2026-41294? +
What products are affected by CVE-2026-41294? +
How do I check if I'm vulnerable to CVE-2026-41294? +
Related Vulnerabilities
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata …
OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. …
Socket Firewall is an HTTP/HTTPS proxy server that intercepts package manager requests and enforces security policies by blocking dangerous packages. …
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. …
Via the GUI of the "bestinformed Infoclient", a low-privileged user is by default able to change the server address of …