PT-2026-34770 · Openclaw · Openclaw
Wang Dong
·
Published
2026-04-07
·
Updated
2026-04-25
·
CVE-2026-41339
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.2
Description
Authenticated clients without administrative privileges can access
configPath and stateDir metadata within Gateway connect success snapshots. This exposure allows non-admin clients to recover host-specific filesystem paths and deployment details, which can be used for host fingerprinting and to facilitate chained attacks.Recommendations
Update to version 2026.4.2.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw