CVE-2026-41330CWE-453

OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy

Low · published April 20, 2026

CVSS v4.0
2.0
EPSS
0%
Percentile
2.4
In the wild
Unconfirmed
What it is

OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to properly enforce proxy, TLS, Docker, and Git TLS controls. Attackers can bypass security controls by overriding environment variables to circumvent proxy settings, TLS verification, Docker restrictions, and Git TLS enforcement.

The record
Technical detail
CVSS v4.0
2.0 · LOW
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS
0.00124 · 2.4th percentile
Weakness
CWE-453 · Insecure Default Variable Initialization
Published
2026-04-20T23:08Z
EPSS history
Timeline
  • 20 APR 23:08Z
    OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy
    cvelistv5