Loading
Generated remediation guidance and an executive summary. No account required.
OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can exploit positional carrier executable routing through dispatch wrappers to establish broader allowlist entries than intended, weakening execution approval boundaries.
No affected products information available.
Cite this page
CVE-2026-41380. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-41380
Use CWE-807 to widen CVE-2026-41380 into its surrounding weakness, vendor, and product context.