PT-2026-24945 · Openclaw · Openclaw
Nedlir
·
Publicado
2026-02-19
·
Atualizado
2026-03-13
·
CVE-2026-4040
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.19-beta.1
Description
An issue exists in OpenClaw related to information disclosure within the
tools.exec.safeBins function of the File Existence Handler component. Manipulation of this function can lead to information exposure through discrepancy, requiring local access for exploitation. The issue involves a file-existence oracle where command behavior differs based on whether a file exists on the host filesystem, allowing attackers to probe for file presence and potentially enumerate the filesystem.Recommendations
Upgrade to version 2026.2.19-beta.1 or later to address this issue.
Correção
Side Channel Attack
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openclaw