PT-2026-24945 · Openclaw · Openclaw

Nedlir

·

Publicado

2026-02-19

·

Atualizado

2026-03-13

·

CVE-2026-4040

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.19-beta.1
Description An issue exists in OpenClaw related to information disclosure within the tools.exec.safeBins function of the File Existence Handler component. Manipulation of this function can lead to information exposure through discrepancy, requiring local access for exploitation. The issue involves a file-existence oracle where command behavior differs based on whether a file exists on the host filesystem, allowing attackers to probe for file presence and potentially enumerate the filesystem.
Recommendations Upgrade to version 2026.2.19-beta.1 or later to address this issue.

Correção

Side Channel Attack

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4040
GHSA-6C9J-X93C-RW6J
GHSA-XJJ9-2W6F-JG55

Produtos afetados

Openclaw