CVE-2026-41294 is an environment variable injection vulnerability in OpenClaw versions prior to 2026.3.28. The flaw stems from the application loading .env configuration files from the current working directory before applying trusted state-directory settings, enabling attackers to inject malicious environment variables and override critical runtime and security configurations. This vulnerability affects users working with OpenClaw in shared repositories or workspaces where an attacker can place a malicious .env file. The vulnerability presents a high severity risk with a CVSS score of 8.6, exploitable through local attack vectors requiring minimal complexity and no special privileges, though user interaction is necessary. Successful exploitation could result in complete compromise of confidentiality, integrity, and availability as attackers gain the ability to manipulate security-sensitive settings during application startup. There is currently no evidence of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. The EPSS score of 0.00013 indicates this vulnerability is less frequently targeted compared to the broader CVE population, suggesting limited current community attention or readily available exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.28CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.28CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.