Impact
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature. The flaw allows callers with lower trust levels to access data that should remain within trusted boundaries, enabling attackers to expose sensitive credentials and other confidential information. The exploit is rooted in improper handling of input paths and feature accessibility, a weakness classified as CWE‑532, which represents unauthorized disclosure of information.
Affected Systems
The affected product is OpenClaw, any installation of OpenClaw prior to version 2026.6.1, running on Node.js environments as listed in the CPE data. All customers using the trajectory export feature in these versions are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.1 indicates a moderate severity with moderate impact. The EPSS score of less than 1% signifies a low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers would need to target the trajectory export function, likely through misconfigured input paths or by abusing feature accessibility controls. No publicly disclosed exploits are known at this time.
OpenCVE Enrichment