Security fixes and advisories that landed overnight. One advisory is included in this update. The item below covers an OpenClaw issue that affects startup configuration handling. Updated 21 Apr 2026 00:16 GMT.
Top items
NIST
CVE-2026-41294
OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration. That lets an attacker place a malicious .env file in a repository or workspace and override runtime configuration and security-sensitive environment settings during startup.
- Published: 21 Apr 2026 00:16 GMT
- CVEs: CVE-2026-41294
- Notes: environment variable injection

