Количество 2
Количество 2
CVE-2026-41339
OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin authenticated clients. Non-admin clients can recover host-specific filesystem paths and deployment details, enabling host fingerprinting and facilitating chained attacks.
GHSA-2f7j-rp58-mr42
OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41339 OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin authenticated clients. Non-admin clients can recover host-specific filesystem paths and deployment details, enabling host fingerprinting and facilitating chained attacks. | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
GHSA-2f7j-rp58-mr42 OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients | CVSS3: 4.3 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу