PT-2026-34770 · Openclaw · Openclaw
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.2
Description
Authenticated clients without administrative privileges can access
configPath and stateDir metadata within Gateway connect success snapshots. This exposure allows non-admin clients to recover host-specific filesystem paths and deployment details, which can be used for host fingerprinting and to facilitate chained attacks.Recommendations
Update to version 2026.4.2.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw