Description
OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.
Published: 2026-07-08
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw before 2026.5.28 contains a credential exposure vulnerability (CWE‑184) where workspace dotenv files can override provider credentials. This flaw can be triggered when an attacker has lower‑trust access to the configured input paths, enabling the reading or manipulation of files that store sensitive configuration. Consequently, credentials that should remain within trusted boundaries can be exposed or replaced, potentially giving the attacker unauthorized access to dependent services or data.

Affected Systems

The affected product is OpenClaw. Versions earlier than 2026.5.28 are susceptible to this credential override flaw. All releases of OpenClaw from 2026.5.28 onward include the vendor‑supplied fix described in the advisory.

Risk and Exploitability

The CVSS score of 8.4 classifies the issue as high severity, indicating a significant impact if exploited. The EPSS score of <1% suggests that exploitation is currently rare in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The attack could be carried out by an entity that has lower‑trust or local access to the workspace input path, such as an attacker with limited file‑system permissions, who could place a malicious dotenv file to override credentials. No confirmed remote exploitation is reported, so a local or privilege‑Escalation vector is inferred.

Generated by OpenCVE AI on July 28, 2026 at 09:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to version 2026.5.28 or later to apply the vendor-supplied fix.
  • If upgrading is not possible, disable the dotenv override feature or delete any workspace dotenv files from the configuration directory to prevent credential overriding.
  • Restrict filesystem permissions on the workspace directories so that only trusted users can modify or read dotenv files.

Generated by OpenCVE AI on July 28, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.
Title OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-184
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-20T17:45:55.824Z

Reserved: 2026-07-04T12:17:14.302Z

Link: CVE-2026-59261

cve-icon Vulnrichment

Updated: 2026-07-08T16:50:11.238Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:15:06Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs