VulnerabilityAnalyzed
CVE-2026-41915
OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host exec operations.
MEDIUM 5.8EPSS 0.11%
Does this matter?
Lower severity and a low EPSS score (0.11%). Track it; it rarely justifies an emergency change on its own.
Description
OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host exec operations. Attackers can exploit this by setting GIT_DIR and related variables to redirect git operations and compromise repository integrity.
- CVSS 4.0
- 5.8 MEDIUMCVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.11% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-184
- Affected
- openclaw/openclaw
- Source
- disclosure@vulncheck.com
References
- https://github.com/openclaw/openclaw/commit/d7c3210cd6f5fdfdc1beff4c9541673e814354d5Patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-cm8v-2vh9-cxf3Vendor Advisory
- https://www.vulncheck.com/advisories/openclaw-git-environment-variable-injection-via-unfiltered-exec-environmentThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.