


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts …
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 21:20:20
Source:
nvd.nist.gov
Supply Chain & Dependencies
OpenClaw versions before 2026.3.22 contain an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts files. This vulnerability allows attackers to override package-manager environment variables through approved exec requests. Attackers can exploit this to redirect package resolution or runtime bootstrap processes to attacker-controlled infrastructure. The vulnerability enables execution of trojanized content through supply chain attacks. This represents a significant supply chain security risk for applications using affected OpenClaw versions.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41387
https://github.com/openclaw/openclaw/security/advisories/GHSA-j7p2-qcwm-94v4
https://www.vulncheck.com/advisories/openclaw-supply-chain-redirection-via-incomplete-host-environment-sanitization
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
