MEDIUM
OpenClaw < 2026.4.2 - Information Disclosure via Gateway Connect Snapshot
Published Apr 23, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.37%
Description
OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin authenticated clients. Non-admin clients can recover host-specific filesystem paths and deployment details, enabling host fingerprinting and facilitating chained attacks.
Affected products
-
Affected
- ≥ 0, < 2026.4.2
Unaffected
- 2026.4.2
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.4.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.4.2 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25323 Advisory
- https://github.com/advisories/GHSA-2f7j-rp58-mr42 Advisory
- https://github.com/openclaw/openclaw/commit/676b748056b5efca6f1255708e9dd9469edf5e2e patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-2f7j-rp58-mr42 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41339
- https://www.vulncheck.com/advisories/openclaw-information-disclosure-via-gateway-connect-snapshot third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25323 | Advisory | |
| https://github.com/advisories/GHSA-2f7j-rp58-mr42 | Advisory | |
| https://github.com/openclaw/openclaw/commit/676b748056b5efca6f1255708e9dd9469edf5e2e | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-2f7j-rp58-mr42 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41339 | ||
| https://www.vulncheck.com/advisories/openclaw-information-disclosure-via-gateway-connect-snapshot | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 23, 2026
Updated Apr 24, 2026
Reserved Apr 20, 2026
Link CVE-2026-41339
CISA Vulnrichment
Updated Apr 24, 2026
Red Hat
No data
GitHub
Link GHSA-2F7J-RP58-MR42