CVE-2026-41368: OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter Bypass
OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the $ENV filter. Attackers can bypass safe-bin restrictions by using $ENV in jq programs to access sensitive environment variables that should be restricted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.3.28
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41368?
CVE-2026-41368 is classified as a medium severity vulnerability due to its potential for environment variable disclosure.
How do I fix CVE-2026-41368?
To fix CVE-2026-41368, upgrade OpenClaw to version 2026.3.28 or later.
What does CVE-2026-41368 affect?
CVE-2026-41368 affects OpenClaw versions prior to 2026.3.28 that utilize the jq $ENV filter.
What is the vulnerability in CVE-2026-41368?
The vulnerability in CVE-2026-41368 allows attackers to bypass safe-bin restrictions and disclose environment variables.
Can CVE-2026-41368 be exploited remotely?
Yes, CVE-2026-41368 can potentially be exploited remotely if an attacker can execute jq programs on the affected system.