CVE-2026-41915
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Apr 28, 2026
Vendor
unknown
Description
OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host exec operations. Attackers can exploit this by setting GIT_DIR and related variables to redirect git operations and compromise repository integrity.