Security Advisory – 21 Apr 2026

Security fixes and advisories that landed overnight. One advisory is included in this update. The item below covers an OpenClaw issue that affects startup configuration handling. Updated 21 Apr 2026 00:16 GMT.

Top items

NIST

CVE-2026-41294

OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration. That lets an attacker place a malicious .env file in a repository or workspace and override runtime configuration and security-sensitive environment settings during startup.

  • Published: 21 Apr 2026 00:16 GMT
  • CVEs: CVE-2026-41294
  • Notes: environment variable injection

Related posts

NocoDB | 2026.04.2

NocoDB 2026 04 2: NocoDocs embedded editor, real time collaboration, Editors can manage collaborative views, UI and field fixes, bug fixes and 2FA progress

n8n | stable

n8n 2 17 5: enforces credential access for dynamic node parameters, fixes credential exposure risk, upgrade recommended for admins and self hosted users

Security Advisory – 21 Apr 2026

Daily security advisory summary for 21 Apr 2026