Executive brief
OpenClaw, a tool used for infrastructure execution, contains a security flaw in how it handles data processing commands. An attacker with low-level access can bypass security restrictions to view sensitive system environment variables, such as API keys or passwords. This could lead to the exposure of confidential credentials and further unauthorized access to connected systems.
Technical details
An environment variable disclosure vulnerability exists in OpenClaw's 'safe-bin' execution policy, specifically within the 'src/infra/exec-safe-bin-semantics.ts' component. While the policy was intended to restrict access to the system environment, it failed to account for the '$ENV' filter in jq programs. A remote attacker with low privileges can execute crafted jq commands to bypass these restrictions and extract sensitive environment variables. This issue is rooted in an incorrect regular expression or insufficient filtering of jq syntax. The vulnerability is addressed in version 2026.3.28 by tightening the jq safe-bin environment checks.
Affected products
- OpenClaw OpenClaw < 2026.3.28
Timeline
- 2026-03-29: advisory: GitHub Security Advisory GHSA-jccr-rrw2-vc8h published
- 2026-04-27: disclosed: CVE-2026-41368 assigned and published to NVD
- 2026-03-28: patched: Version 2026.3.28 released with fix