PT-2026-35768 · Openclaw · Openclaw

Jufeng123768

·

Published

2026-04-07

·

Updated

2026-05-01

·

CVE-2026-41383

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.2
Description An arbitrary directory deletion issue exists in mirror mode. Attackers can delete remote directories by influencing the remoteWorkspaceDir and remoteAgentWorkspaceDir configuration values. By manipulating these OpenShell config paths, attackers can cause mirror sync operations to delete unintended remote directory contents and replace them with uploaded workspace data.
Recommendations Update to version 2026.4.2.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-41383
GHSA-M34Q-H93W-VG5X

Affected Products

Openclaw