Security Advisory

CVE-2026-41368

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-27 23:24:30
Last updated 2026-04-28 12:43:15
Assigner VulnCheck
CVSS score 7.1
State PUBLISHED

Description

OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the $ENV filter. Attackers can bypass safe-bin restrictions by using $ENV in jq programs to access sensitive environment variables that should be restricted.