PT-2026-34766 · Openclaw · Openclaw

Wang Dong

·

Published

2026-04-03

·

Updated

2026-04-25

·

CVE-2026-41335

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description An information disclosure issue exists in the Control Interface bootstrap JSON. This allows attackers to extract sensitive fingerprinting information, specifically version and assistant agent identifiers, from the Control UI bootstrap payload to identify system versions and agent configurations.
Recommendations Update to version 2026.3.31.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-41335
GHSA-FJM8-MGC9-MF65
GHSA-HR8G-2Q7X-3F4W

Affected Products

Openclaw