CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ⬡ Vulnerabilities & CVEs Apr 24, 2026

CVE-2026-41336 | OpenClaw up to 2026.3.30 Environment Variable OPENCLAW_BUNDLED_HOOKS_DIR inclusion of functionality from untrusted control sphere (GHSA-3qpv-xf3v-mm45)

VulDB Archived Apr 24, 2026 ! Full text unavailable

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.3.30 . This issue affects some unknown processing of the component Environment Variable Handler . The manipulation of the argument OPENCLAW_BUNDLED_HOOKS_DIR leads to inclusion of functionality from untrusted control sphere. This vulnerability is uniquely identified as CVE-2026-41336 . Local access is required to approach this attack. No exploit exists. It is advisable to upgrade the affected component.

Full text unavailable — view original
✦ AI Summary · Claude Sonnet


    Full text unavailable.
    Open original ↗
    💬 Team Notes
    Article Info
    Source
    VulDB
    Category
    ⬡ Vulnerabilities & CVEs
    Published
    Apr 24, 2026
    Archived
    Apr 24, 2026
    Full Text
    ✗ Not available
    Open Original ↗