Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jufeng123768

#31367of 53,624
8.1Total CVSS
Vulnerabilities · 1
PT-2026-35768
8.1
2026-04-07
Openclaw · Openclaw · CVE-2026-41383
**Name of the Vulnerable Software and Affected Versions** OpenClaw versions prior to 2026.4.2 **Description** An arbitrary directory deletion issue exists in mirror mode. Attackers can delete remote directories by influencing the `remoteWorkspaceDir` and `remoteAgentWorkspaceDir` configuration values. By manipulating these OpenShell config paths, attackers can cause mirror sync operations to delete unintended remote directory contents and replace them with uploaded workspace data. **Recommendations** Update to version 2026.4.2.