CVE-2026-41355

7.3

OpenClaw · OpenClaw

OpenClaw before 2026.3.28 is vulnerable to arbitrary code execution in mirror mode when processing untrusted sandbox files into workspace hooks.

Executive summary

A critical arbitrary code execution vulnerability in OpenClaw allows attackers with mirror mode access to execute code on the host system during gateway startup.

Vulnerability

The software suffers from an inclusion of functionality from an untrusted control sphere (CWE-829). An authenticated user with mirror mode access can trigger arbitrary code execution on the host by converting malicious sandbox files into workspace hooks during the gateway startup process.

Business impact

The ability for an attacker to execute arbitrary code on the host system represents a complete compromise of the application environment. Given the CVSS score of 7.3, this flaw poses a high risk to business operations, potentially leading to unauthorized data access, lateral movement within the network, or complete system takeover.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.3.28 or later to incorporate the upstream fix.

Proactive Monitoring: Review system logs for unusual gateway startup behaviors or unauthorized modifications to workspace hook configurations.

Compensating Controls: Restrict access to mirror mode functionality to trusted users only and implement strict file system permissions to prevent the placement of untrusted sandbox files.

Exploitation status

Public Exploit Available: No confirmed public exploit (weaponized or otherwise) is available in the provided data.

Analyst recommendation

Organizations utilizing OpenClaw must prioritize updating to version 2026.3.28 immediately to neutralize the risk of arbitrary code execution. Because this vulnerability allows for full host compromise, failure to apply the update leaves the infrastructure exposed to potential remote or local attackers who gain access to the mirror mode environment.

More OpenClaw CVEs

Sources

Originally found and disclosed by tdjackey, per the CVE Program record.