Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2f7j-rp58-mr42

Опубликовано: 07 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients

Summary

Before OpenClaw 2026.4.2, the Gateway connect success snapshot exposed local configPath and stateDir metadata to non-admin clients. Low-privilege authenticated clients could learn host filesystem layout and deployment details that were not needed for their role.

Impact

A non-admin client could recover host-specific filesystem paths and related deployment metadata, aiding host fingerprinting and chained attacks. This was an information-disclosure issue, not a direct authorization bypass.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected versions: <= 2026.4.1
  • Patched versions: >= 2026.4.2
  • Latest published npm version: 2026.4.1

Fix Commit(s)

  • 676b748056b5efca6f1255708e9dd9469edf5e2e — limit connect snapshot metadata to admin-scoped clients

Release Process Note

The fix is present on main and is staged for OpenClaw 2026.4.2. Publish this advisory after the 2026.4.2 npm release is live.

Thanks @topsec-bunney for reporting.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

<= 2026.4.1

2026.4.2

EPSS

Процентиль: 21%
0.00283
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
3 месяца назад

OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin authenticated clients. Non-admin clients can recover host-specific filesystem paths and deployment details, enabling host fingerprinting and facilitating chained attacks.

EPSS

Процентиль: 21%
0.00283
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200