CVE-2026-41380

OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can exploit positional carrier executable routing through dispatch wrappers to establish broader allowlist entries than intended, weakening execution approval boundaries.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

01 May 2026, 15:51

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-p4x4-2r7f-wjxg - () https://github.com/openclaw/openclaw/security/advisories/GHSA-p4x4-2r7f-wjxg - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-arbitrary-execution-allowlist-via-wrapper-carrier-executables - () https://www.vulncheck.com/advisories/openclaw-arbitrary-execution-allowlist-via-wrapper-carrier-executables - Third Party Advisory
First Time Openclaw openclaw
Openclaw

28 Apr 2026, 19:37

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 19:37

Updated : 2026-05-01 15:51


NVD link : CVE-2026-41380

Mitre link : CVE-2026-41380

CVE.ORG link : CVE-2026-41380


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-807

Reliance on Untrusted Inputs in a Security Decision