CVE-2026-41369
OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, regist
CVSS
6.5
Medio
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Publicado: 28 abr 2026 · Última mod.: 24 jul 2026 · CWE-668
0.3%EPSS · 30 días0.3%
2026-08-132026-09-09
OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environment variables to override critical system configurations and compromise host execution integrity.
- github.comhttps://github.com/openclaw/openclaw/commit/eb8de6715f02949c21c4e895fffc8a6dcb00975c
- github.comhttps://github.com/openclaw/openclaw/security/advisories/GHSA-cg7q-fg22-4g98
- www.vulncheck.comhttps://www.vulncheck.com/advisories/openclaw-insufficient-environment-variable-sanitization-in-host-execution
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-850538.8 ALT21.9%
——7Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)3dCVE-2026-826525.3 MED10.6%
——3SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.11dCVE-2026-826504.4 MED12.4%
——4SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint restricts the supplied path only to the workspace directory (util.IsAbsPathInWorkspace) but, unlike the file API's refuseToAccess() blocklist, applies no sensitive-path exclusion. This allows an authenticated attacker to read sensitive workspace files, including conf/conf.json, which contains the API token and cookie signing key. The issue is fixed in v3.8.1.11dCVE-2026-790684.3 MED10.9%
——3Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)11dCVE-2026-790313.1 BAJ26.2%
——8Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)14dCVE-2026-593084.2 MED5.3%
——2In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts.
Affected versions:
Spring AI: 2.0.014d