MEDIUM
OpenClaw < 2026.4.2 - Arbitrary Remote Directory Deletion via Mis-scoped Mirror Mode Paths
Published Apr 28, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.58%
Description
OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by influencing remoteWorkspaceDir and remoteAgentWorkspaceDir configuration values. Attackers can manipulate these OpenShell config paths to cause mirror sync operations to delete unintended remote directory contents and replace them with uploaded workspace data.
Affected products
-
- Version 0StatusaffectedConstraints<2026.4.2
- Version 2026.4.2StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.4.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.4.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/advisories/GHSA-m34q-h93w-vg5x Advisory
- https://github.com/openclaw/openclaw/commit/b21c9840c2e38f4bb338d031511b479d5f07ca25 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-m34q-h93w-vg5x vendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-arbitrary-remote-directory-deletion-via-mis-scoped-mirror-mode-paths third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-m34q-h93w-vg5x | Advisory | |
| https://github.com/openclaw/openclaw/commit/b21c9840c2e38f4bb338d031511b479d5f07ca25 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-m34q-h93w-vg5x | vendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-arbitrary-remote-directory-deletion-via-mis-scoped-mirror-mode-paths | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 28, 2026
Updated Apr 29, 2026
Reserved Apr 20, 2026
Link CVE-2026-41383
CISA Vulnrichment
GHSA-M34Q-H93W-VG5X Updated Apr 29, 2026