CVE-2026-41373 | OpenClaw up to 2026.3.30 host-env-security-policy.json uncontrolled search path (GHSA-g8xp-qx39-9jq9)
A vulnerability labeled as problematic has been found in OpenClaw up to 2026.3.30. This impacts an unknown function of the file host-env-security-policy.json. The manipulation results in uncontrolled search path.
This vulnerability is identified as CVE-2026-41373. The attack is only possible with local access. There is not any exploit available.
The affected component should be upgraded.