Description
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.
Published: 2026-07-17
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature. The flaw allows callers with lower trust levels to access data that should remain within trusted boundaries, enabling attackers to expose sensitive credentials and other confidential information. The exploit is rooted in improper handling of input paths and feature accessibility, a weakness classified as CWE‑532, which represents unauthorized disclosure of information.

Affected Systems

The affected product is OpenClaw, any installation of OpenClaw prior to version 2026.6.1, running on Node.js environments as listed in the CPE data. All customers using the trajectory export feature in these versions are potentially vulnerable.

Risk and Exploitability

The CVSS score of 4.1 indicates a moderate severity with moderate impact. The EPSS score of less than 1% signifies a low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers would need to target the trajectory export function, likely through misconfigured input paths or by abusing feature accessibility controls. No publicly disclosed exploits are known at this time.

Generated by OpenCVE AI on July 31, 2026 at 00:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to OpenClaw version 2026.6.1 or later, which contains the fix for the credential redaction bypass.
  • Disable or restrict the trajectory export feature for callers that do not have the necessary trust level until the patch is applied.
  • Audit export path configurations and enforce strict access controls to ensure only authorized users can invoke the export functionality.

Generated by OpenCVE AI on July 31, 2026 at 00:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.
Title OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-532
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 4.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-29T20:13:58.980Z

Reserved: 2026-07-13T16:39:22.251Z

Link: CVE-2026-62211

cve-icon Vulnrichment

Updated: 2026-07-29T20:13:56.438Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File