Medium severity6.5NVD Advisory· Published Apr 28, 2026· Updated Apr 28, 2026
CVE-2026-41368
CVE-2026-41368
Description
OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the $ENV filter. Attackers can bypass safe-bin restrictions by using $ENV in jq programs to access sensitive environment variables that should be restricted.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-jccr-rrw2-vc8hnvdVendor Advisory
- www.vulncheck.com/advisories/openclaw-environment-variable-disclosure-via-jq-env-filter-bypassnvdThird Party Advisory
News mentions
0No linked articles in our index yet.