CVE-2026-41388
OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array s
OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array settings as missing values. Attackers can restart the application to rehydrate revoked Tlon configuration from file state, bypassing intended revocation controls.
MEDIUM · CVSS 6.5
EPSS 0.00041
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0