CVE-2026-41369 — OpenClaw before 2026.3.31 contains insufficient environment
CVE-2026-41369 — OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environment variables to override critical
What This Means For You
- If your environment is affected by CWE-668, review your exposure and prioritize patching based on your environment. Monitor vendor advisories for CVE-2026-41369 updates and patches.
Related ATT&CK Techniques
🛡️ Detection Rules
3 rules · 6 SIEM formats3 detection rules auto-generated for this incident, mapped to MITRE ATT&CK. Sigma YAML is free — export to any SIEM format via the Intel Bot.
CVE-2026-41369 - OpenClaw Host Exec Environment Variable Override
title: CVE-2026-41369 - OpenClaw Host Exec Environment Variable Override
id: scw-2026-04-28-ai-1
status: experimental
level: high
description: |
Detects the exploitation of CVE-2026-41369 by identifying processes related to OpenClaw that are launched with suspicious environment variables known to be vulnerable to injection. This includes variables like LD_PRELOAD, PYTHONPATH, NODE_OPTIONS, DOCKER_HOST, and SSLKEYLOGFILE, which can be used to override critical system configurations and execute arbitrary code.
author: SCW Feed Engine (AI-generated)
date: 2026-04-28
references:
- https://shimiscyberworld.com/posts/nvd-CVE-2026-41369/
tags:
- attack.execution
- attack.t1059.004
logsource:
category: process_creation
detection:
selection:
Image|contains:
- 'OpenClaw'
CommandLine|contains:
- 'LD_PRELOAD='
- 'PYTHONPATH='
- 'NODE_OPTIONS='
- 'DOCKER_HOST='
- 'SSLKEYLOGFILE='
condition: selection
falsepositives:
- Legitimate administrative activity
Source: Shimi's Cyber World · License & reuse
Indicators of Compromise
| ID | Type | Indicator |
|---|---|---|
| CVE-2026-41369 | vulnerability | CVE-2026-41369 |
| CWE-668 | weakness | CWE-668 |
Source & Attribution
| Source Platform | NVD |
| Channel | National Vulnerability Database |
| Published | April 28, 2026 at 03:16 UTC |
This content was curated and summarized by Shimi's Cyber World for informational purposes. It is not copied or republished in full. All intellectual property rights remain with the original author and source.
Believe this infringes your rights? Submit a takedown request.