CVE-2026-41332 | OpenClaw up to 2026.3.27 Environment Variable GIT_TEMPLATE_DIR/AWS_CONFIG_FILE incomplete blacklist (GHSA-m866-6qv5-p2fg)
A vulnerability, which was classified as critical, was found in OpenClaw up to 2026.3.27. This affects an unknown part of the component Environment Variable Handler. Executing a manipulation of the argument GIT_TEMPLATE_DIR/AWS_CONFIG_FILE can lead to incomplete blacklist.
The identification of this vulnerability is CVE-2026-41332. The attack can only be executed locally. There is no exploit available.
You should upgrade the affected component.