Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41294

29
FAUCET Score

CVE-2026-41294 is an environment variable injection vulnerability in OpenClaw versions prior to 2026.3.28. The flaw stems from the application loading .env configuration files from the current working directory before applying trusted state-directory settings, enabling attackers to inject malicious environment variables and override critical runtime and security configurations. This vulnerability affects users working with OpenClaw in shared repositories or workspaces where an attacker can place a malicious .env file. The vulnerability presents a high severity risk with a CVSS score of 8.6, exploitable through local attack vectors requiring minimal complexity and no special privileges, though user interaction is necessary. Successful exploitation could result in complete compromise of confidentiality, integrity, and availability as attackers gain the ability to manipulate security-sensitive settings during application startup. There is currently no evidence of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. The EPSS score of 0.00013 indicates this vulnerability is less frequently targeted compared to the broader CVE population, suggesting limited current community attention or readily available exploit code.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2026.3.28CPE match
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
< 2026.3.28CPE matchmatch criteria
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.5HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
3.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 1st percentile among its peer group of 11,621 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

npmpatch availablevia ghsa
Product: openclawFixed in: 2026.3.28
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-8rh7-6779-cjqqcritical

OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover

Apr 1, 2026

References

github.com / openclaw/openclaw/security/advisories/GHSA-8rh7-6779-cjqq
Vendor Advisory
vulncheck.com / advisories/openclaw-environment-variable-injection-via-cwd-env-file
Third Party Advisory