Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Longgteng

#40333of 56,333
7.3Total CVSS
Vulnerabilities · 1
PT-2026-35774
7.3
2026-03-31
Openclaw · Openclaw · CVE-2026-41390
**Name of the Vulnerable Software and Affected Versions** OpenClaw versions prior to 2026.3.28 **Description** An exec allowlist bypass exists where allow-always persistence fails to unwrap `/usr/bin/script` and similar wrappers before storing trust decisions. This allows attackers to obtain user approval for a single wrapped command to persist trust for wrapper binaries that execute different underlying programs. **Recommendations** Update to version 2026.3.28.