Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xmvq-76g8-6jhm

Опубликовано: 17 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.1
CVSS3: 5

Описание

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.

EPSS

Процентиль: 2%
0.00111
Низкий

4.1 Medium

CVSS4

5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5
nvd
27 дней назад

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.

EPSS

Процентиль: 2%
0.00111
Низкий

4.1 Medium

CVSS4

5 Medium

CVSS3

Дефекты

CWE-532