CVE-2026-41360: OpenClaw < 2026.4.2 - Approval Integrity Bypass in pnpm dlx Local Script Binding
OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. Attackers can replace approved local scripts before execution without invalidating the approval plan, allowing execution of modified script contents.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41360?
The severity of CVE-2026-41360 is classified as high due to its potential for exploitation through script replacements.
How do I fix CVE-2026-41360?
To fix CVE-2026-41360, upgrade OpenClaw to version 2026.4.2 or later.
What type of vulnerability is CVE-2026-41360?
CVE-2026-41360 is an approval integrity bypass vulnerability affecting local script bindings.
Who is affected by CVE-2026-41360?
Users of OpenClaw versions prior to 2026.4.2 are affected by CVE-2026-41360.
What can attackers do with CVE-2026-41360?
Attackers can replace approved local scripts before execution, allowing for unauthorized commands to be run.