CVE-2026-41360

medium
Published 2026-04-23 · Modified 2026-05-01
CVSS v3
6.7
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
6.7

Description

OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. Attackers can replace approved local scripts before execution without invalidating the approval plan, allowing execution of modified script contents.

Predictions

Exploit likelihood
66%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/security/advisories/GHSA-w6wx-jq6j-6mcj

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/176c059b05357df1bc09d4328a2380670859eeff

Application impact

VendorProductVersionsFixed
openclawopenclaw{"endExcluding":"2026.4.2"}2026.4.2

References

CWEs

CWE-367

Verify integrity in audit chain (admin only). AS-IS.