Security Advisory – 21 Apr 2026

Security fixes and advisories that landed overnight. One advisory is included in this update. The item below covers an OpenClaw issue that affects startup configuration handling. Updated 21 Apr 2026 00:16 GMT.

Top items

NIST

CVE-2026-41294

OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration. That lets an attacker place a malicious .env file in a repository or workspace and override runtime configuration and security-sensitive environment settings during startup.

  • Published: 21 Apr 2026 00:16 GMT
  • CVEs: CVE-2026-41294
  • Notes: environment variable injection

Related posts

Metadata schema choices for content libraries

Structured metadata only works when it matches how people actually retrieve content. I have seen neat schemas fail as soon as the library meets real records, and tarot makes the problem obvious. If...

Federation trade-offs in self-hosted social feeds

Federation looks tidy until you let it touch the edges, and then the odd cases arrive fast. I prefer self-hosted social feeds that stay explicit about what is local, what is remote, and what should...

FireAvert Z-Wave stove shutoffs for offline safety

FireAvert’s setup does the part that matters without asking Home Assistant to babysit it, which is exactly how I want stove protection to behave. The Home Assistant Z-Wave stove shutoffs badge is...