CVE-2026-41390: OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapper
(updated )
Allow-always persistence did not unwrap /usr/bin/script and similar wrappers to the actual executed target before storing trust decisions.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-41390 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →