Openclaw cli: OpenClaw: pnpm dlx approvals did not bind local script operands (CVE-2026-41360)
Description
OpenClaw CLI versions before 2026.4.2 have an approval-integrity vulnerability in the pnpm dlx command. The issue allows a local script approved via pnpm dlx to be replaced before execution without invalidating the approval, potentially enabling execution of modified script contents. This flaw affects versions from 2026.1.29 up to but not including 2026.4.2. The vulnerability is fixed in version 2026.4.2.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Before OpenClaw 2026.4.2, the pnpm dlx approval planning process did not bind local script operands consistently with pnpm exec flows. This discrepancy allowed an attacker or operator to approve a benign local script and then replace the script contents before execution without invalidating the approval plan. This is an approval-integrity bug in the node-host command-planning path. The issue was fixed by binding local scripts in pnpm dlx approval plans in commit 176c059b05357df1bc09d4328a2380670859eeff and released in OpenClaw 2026.4.2.
Potential Impact
An operator could approve a local script considered safe, but then execute a modified version of that script under the same approval, potentially leading to unintended or malicious script execution. This undermines the integrity of the approval process in the pnpm dlx command flow.
Mitigation Recommendations
A fix is available in OpenClaw version 2026.4.2 and later. Users should upgrade to version 2026.4.2 or newer to ensure local script operands are properly bound and approval integrity is maintained.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-41360
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac245a112601ec6a3165d8b
Added to database: 10/04/2026, 12:25:05 UTC
Last enriched: 10/04/2026, 12:48:52 UTC
Last updated: 10/04/2026, 16:08:38 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.