CVE-2026-41360
MEDIUMOpenClaw < 2026.4.2 - Approval Integrity Bypass in pnpm dlx Local Script Binding
Title source: cnaDescription
OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. Attackers can replace approved local scripts before execution without invalidating the approval plan, allowing execution of modified script contents.
Scores
CVSS v3
6.7
EPSS
0.0001
EPSS Percentile
1.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-367
Status
published
Products (2)
OpenClaw/OpenClaw
< 2026.4.2
OpenClaw/OpenClaw
2026.4.2
Published
Apr 23, 2026
Tracked Since
Apr 24, 2026