CVE-2026-41396
OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_PLUGINS_DIR environment variable,
OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_PLUGINS_DIR environment variable, compromising plugin trust verification. Attackers with control over workspace configuration can inject malicious plugins by overriding the bundled plugin trust root directory.
HIGH · CVSS 7.8
EPSS 0.00014
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0