Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rwrg-63c8-2784

Опубликовано: 08 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.4
CVSS3: 7.1

Описание

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.

EPSS

Процентиль: 19%
0.00273
Низкий

8.4 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-184
CWE-522

Связанные уязвимости

CVSS3: 7.1
nvd
около 2 месяцев назад

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.

EPSS

Процентиль: 19%
0.00273
Низкий

8.4 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-184
CWE-522