CVE-2026-41360

MEDIUM

OpenClaw < 2026.4.2 - Approval Integrity Bypass in pnpm dlx Local Script Binding

Title source: cna

Description

OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. Attackers can replace approved local scripts before execution without invalidating the approval plan, allowing execution of modified script contents.

Scores

CVSS v3 6.7
EPSS 0.0001
EPSS Percentile 1.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-367
Status published
Products (2)
OpenClaw/OpenClaw < 2026.4.2
OpenClaw/OpenClaw 2026.4.2
Published Apr 23, 2026
Tracked Since Apr 24, 2026